CVE-2025-15572

A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation leads to memory leak. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Unfortunately, the project has no active maintainer at the moment.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:wasm3_project:wasm3:*:*:*:*:*:*:*:*

History

29 Apr 2026, 01:00

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido encontrada en wasm3 hasta 0.5.0. El elemento afectado es la función NewCodePage. La manipulación conduce a una fuga de memoria. El ataque debe llevarse a cabo localmente. El exploit ha sido divulgado al público y puede ser utilizado. Desafortunadamente, el proyecto no tiene un mantenedor activo en este momento.

12 Feb 2026, 15:22

Type Values Removed Values Added
References () https://github.com/oneafter/cve-proofs/blob/main/POC-20251203-07/repro - () https://github.com/oneafter/cve-proofs/blob/main/POC-20251203-07/repro - Exploit
References () https://github.com/wasm3/wasm3/ - () https://github.com/wasm3/wasm3/ - Product
References () https://github.com/wasm3/wasm3/issues/550 - () https://github.com/wasm3/wasm3/issues/550 - Exploit, Issue Tracking
References () https://vuldb.com/?ctiid.344934 - () https://vuldb.com/?ctiid.344934 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.344934 - () https://vuldb.com/?id.344934 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.752765 - () https://vuldb.com/?submit.752765 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:wasm3_project:wasm3:*:*:*:*:*:*:*:*
First Time Wasm3 Project
Wasm3 Project wasm3

10 Feb 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 16:16

Updated : 2026-04-29 01:00


NVD link : CVE-2025-15572

Mitre link : CVE-2025-15572

CVE.ORG link : CVE-2025-15572


JSON object : View

Products Affected

wasm3_project

  • wasm3
CWE
CWE-401

Missing Release of Memory after Effective Lifetime

CWE-404

Improper Resource Shutdown or Release