VulnerabilityAnalyzed
CVE-2025-15572
A vulnerability has been found in wasm3 up to 0.5.0.
LOW 1.9EPSS 0.16%
Does this matter?
Lower severity and a low EPSS score (0.16%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation leads to memory leak. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Unfortunately, the project has no active maintainer at the moment.
- CVSS 4.0
- 1.9 LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.16% probability · 6th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-401, CWE-404
- Affected
- wasm3 project/wasm3
- Source
- cna@vuldb.com
References
- https://github.com/oneafter/cve-proofs/blob/main/POC-20251203-07/reproExploit
- https://github.com/wasm3/wasm3/Product
- https://github.com/wasm3/wasm3/issues/550Exploit, Issue Tracking
- https://vuldb.com/?ctiid.344934Permissions Required, VDB Entry
- https://vuldb.com/?id.344934Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.752765Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.