← Vulnerability feed

Vulnerability record · CVE-2025-64704 · published 25 November 2025

CVE-2025-64704: Bytecodealliance webassembly micro runtime vulnerability

Bytecodealliance · Webassembly Micro Runtime

WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instruction. This issue has been patched in version 2.4.4.

5.5 CVSS 3.1 Medium EPSS 0.19% · top 92.4% CWE-754 · CWE-754
5.5CVSS 3.1 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instruction. This issue has been patched in version 2.4.4.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-64704 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-25431Bytecodealliance webassembly micro runtime out-of-bounds read vulnerabilityAn issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a cr…EPSS 0.63%7.5CVE-2024-27532Bytecodealliance webassembly micro runtime null pointer dereference vulnerabilitywasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.EPSS 0.51%7.5CVE-2024-34251Bytecodealliance webassembly micro runtime out-of-bounds read vulnerabilityAn out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a den…EPSS 0.76%7.5CVE-2023-48105Bytecodealliance webassembly micro runtime out-of-bounds write vulnerabilityAn heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service v…EPSS 1.0%7.4CVE-2025-64713Bytecodealliance webassembly micro runtime memory buffer overflow vulnerabilityWebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue …EPSS 0.33%7.0CVE-2025-43853Bytecodealliance webassembly micro runtime vulnerabilityThe WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WAS…EPSS 0.28%6.9CVE-2025-54126Bytecodealliance webassembly micro runtime exposure of resource to wrong sphere vulnerabilityThe WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WAS…EPSS 0.63%6.2CVE-2024-34250Bytecodealliance webassembly micro runtime heap-based buffer overflow vulnerabilityA heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2025-64704), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.