CVE-2026-8257
published 2026-05-11CVE-2026-8257: A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.5th percentile
A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion. The attack needs to be approached locally. The exploit is now public and may be used. The patch is named 1251efbc1ea471c1311d2726b2bbe061ff2a291c. It is suggested to install a patch to address this issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| webassembly | binaryen | <= 117 | — |
| webassembly | binaryen | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gmmj-chcc-2f2x: A vulnerability was detected in WebAssembly Binaryen up to 117
ghsa_unreviewed·2026-05-11
CVE-2026-8257 [LOW] CWE-617 GHSA-gmmj-chcc-2f2x: A vulnerability was detected in WebAssembly Binaryen up to 117
A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion. The attack needs to be approached locally. The exploit is now public and may be used. The patch is named 1251efbc1ea471c1311d2726b2bbe061ff2a291c. It is suggested to install a patch to address this issue.
VulDB
WebAssembly Binaryen up to 117 BrOn Parser wasm-ir-builder.cpp IRBuilder::makeBrOn assertion (Issue 8633)
vuldb·2026-05-10
CVE-2026-8257 [LOW] WebAssembly Binaryen up to 117 BrOn Parser wasm-ir-builder.cpp IRBuilder::makeBrOn assertion (Issue 8633)
A vulnerability identified as problematic has been detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion.
This vulnerability was named CVE-2026-8257. The attack needs to be approached locally. In addition, an exploit is available.
It is suggested to install a patch to address this issue.
Citrix
Citrix Security Bulletin CTX282684
vendor_citrix·CVSS 9.8
CVE-2020-8257 [CRITICAL] Citrix Security Bulletin CTX282684
Citrix Security Bulletin CTX282684
CVE References: CVE-2020-8257, CVE-2020-8258, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-8257 binaryen: WebAssembly Binaryen: Denial of Service via manipulation in IRBuilder::makeBrOn [epel-all]
bugzilla·2026-05-11·CVSS 1.9
CVE-2026-8257 [LOW] CVE-2026-8257 binaryen: WebAssembly Binaryen: Denial of Service via manipulation in IRBuilder::makeBrOn [epel-all]
CVE-2026-8257 binaryen: WebAssembly Binaryen: Denial of Service via manipulation in IRBuilder::makeBrOn [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-8257 binaryen: WebAssembly Binaryen: Denial of Service via manipulation in IRBuilder::makeBrOn
bugzilla·2026-05-11·CVSS 1.9
CVE-2026-8257 [LOW] CVE-2026-8257 binaryen: WebAssembly Binaryen: Denial of Service via manipulation in IRBuilder::makeBrOn
CVE-2026-8257 binaryen: WebAssembly Binaryen: Denial of Service via manipulation in IRBuilder::makeBrOn
A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion. The attack needs to be approached locally. The exploit is now public and may be used. The patch is named 1251efbc1ea471c1311d2726b2bbe061ff2a291c. It is suggested to install a patch to address this issue.
https://github.com/HackC0der/CVE-Repos/blob/main/wasm-binaryen/Assertion_Failure_isRef_wasm_Type_getHeapType_commit_3ef8d19https://github.com/WebAssembly/binaryen/https://github.com/WebAssembly/binaryen/commit/1251efbc1ea471c1311d2726b2bbe061ff2a291chttps://github.com/WebAssembly/binaryen/issues/8633https://github.com/WebAssembly/binaryen/pull/8635https://vuldb.com/submit/809552https://vuldb.com/vuln/362554https://vuldb.com/vuln/362554/cti
2026-05-11
Published