CVE-2025-15572 PUBLISHED

wasm3 NewCodePage memory leak

Assigner: VulDB
Reserved: 08.02.2026 Published: 10.02.2026 Updated: 10.02.2026

A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation leads to memory leak. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Unfortunately, the project has no active maintainer at the moment.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 4.8

Product Status

Vendor n/a
Product wasm3
Versions
  • Version 0.1 is affected
  • Version 0.2 is affected
  • Version 0.3 is affected
  • Version 0.4 is affected
  • Version 0.5.0 is affected

Credits

  • Oneafter (VulDB User) reporter

References

Problem Types

  • Memory Leak CWE
  • Denial of Service CWE