← Vulnerability feed

Vulnerability record · CVE-2025-64713 · published 25 November 2025

CVE-2025-64713: Bytecodealliance webassembly micro runtime memory buffer overflow vulnerability

Bytecodealliance · Webassembly Micro Runtime

WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue exists in WAMR's fast interpreter mode during WASM bytecode loading. When frame_ref_bottom and frame_offset_bottom arrays are at capacity and a GET_GLOBAL(I32) opcode is encountered, frame_ref_bottom is expanded but frame_offset_bottom may not be. If this is immediately followed by an if opcode that triggers preserve_local_for_block, the function traverses arrays using stack_cell_num as the upper bound, causing out-of-bounds access to frame_offset_bottom since it wasn't expanded to match the increased stack_cell_num. This issue has been patched in version 2.4.4.

7.4 CVSS 3.1 High EPSS 0.33% · top 76.7% CWE-119 · Memory buffer overflow
7.4CVSS 3.1 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue exists in WAMR's fast interpreter mode during WASM bytecode loading. When frame_ref_bottom and frame_offset_bottom arrays are at capacity and a GET_GLOBAL(I32) opcode is encountered, frame_ref_bottom is expanded but frame_offset_bottom may not be. If this is immediately followed by an if opcode that triggers preserve_local_for_block, the function traverses arrays using stack_cell_num as the upper bound, causing out-of-bounds access to frame_offset_bottom since it wasn't expanded to match the increased stack_cell_num. This issue has been patched in version 2.4.4.

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-64713 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-25431Bytecodealliance webassembly micro runtime out-of-bounds read vulnerabilityAn issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a cr…EPSS 0.63%7.5CVE-2024-27532Bytecodealliance webassembly micro runtime null pointer dereference vulnerabilitywasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.EPSS 0.51%7.5CVE-2024-34251Bytecodealliance webassembly micro runtime out-of-bounds read vulnerabilityAn out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a den…EPSS 0.76%7.5CVE-2023-48105Bytecodealliance webassembly micro runtime out-of-bounds write vulnerabilityAn heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service v…EPSS 1.0%7.0CVE-2025-43853Bytecodealliance webassembly micro runtime vulnerabilityThe WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WAS…EPSS 0.28%6.9CVE-2025-54126Bytecodealliance webassembly micro runtime exposure of resource to wrong sphere vulnerabilityThe WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WAS…EPSS 0.61%6.2CVE-2024-34250Bytecodealliance webassembly micro runtime heap-based buffer overflow vulnerabilityA heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a…EPSS 0.33%5.5CVE-2025-64704Bytecodealliance webassembly micro runtime vulnerabilityWebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentatio…EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2025-64713), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.