VYPR

wasm2c

by Webassembly

CVEs (1)

  • CVE-2026-90648HigSep 13, 2026
    risk 0.39cvss —epss 0.00

    wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl-tableops.inc). When the…