CVE-2024-34251: Bytecodealliance Webassembly Micro Runtime
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h.
Affected products
- Bytecodealliance Webassembly Micro Runtime: version 2.0.0 only
Published 2024-05-06. Last modified 2026-06-17.