CVE-2025-3122
CVSS 3.1 Score 3.1 of 10 (low)
Details
Published Apr 2, 2025
Updated: Apr 7, 2025
CWE ID 404
CWE ID 476
Summary
CVE-2025-3122 is a recently disclosed vulnerability affecting WebAssembly wabt 1.0.36. Specifically, the issue lies within the BinaryReaderInterp::BeginFunctionBody function in src/interp/binary-reader-interp.cc. This vulnerability allows for a null pointer dereference, which can be exploited remotely. However, the attack's complexity is relatively high, making it a challenging exploit to execute. Despite this challenge, the exploit has already been disclosed to the public, increasing the potential for its misuse.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WebAssembly