CVE-2025-14956
Severity CVSS v4.0:
MEDIUM
Type:
CWE-119
Buffer Errors
Publication date:
19/12/2025
Last modified:
19/12/2025
Description
A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReader::readExport of the file src/wasm/wasm-binary.cpp. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Patch name: 4f52bff8c4075b5630422f902dd92a0af2c9f398. It is recommended to apply a patch to fix this issue.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/WebAssembly/binaryen/commit/4f52bff8c4075b5630422f902dd92a0af2c9f398
- https://github.com/WebAssembly/binaryen/issues/8089
- https://github.com/WebAssembly/binaryen/pull/8092
- https://github.com/oneafter/1204/blob/main/hbf
- https://vuldb.com/?ctiid_337592=
- https://vuldb.com/?id_337592=
- https://vuldb.com/?submit_717315=



