Stream: wamr

Topic: Security vulnerability in WAMR


view this post on Zulip Isaac Hung (Feb 24 2026 at 22:11):

Hi WAMR team, I recently found a security vulnerability through fuzzing, and I opened an advisory report on the github. Given that the vulnerability has a pretty high severity, would anybody on the security be able to take a look? Thanks!

https://github.com/bytecodealliance/wasm-micro-runtime/security/advisories/GHSA-hw2g-7rqv-2393

view this post on Zulip Pat Hickey (Feb 24 2026 at 22:18):

cc @Stephen Berard

view this post on Zulip Isaac Hung (Feb 28 2026 at 04:23):

Hi all -- just checking if there are any updates on this?

view this post on Zulip lum1n0us (Mar 01 2026 at 23:53):

Thank you for reporting it. This is a good question about WAMR's security model regarding AOT and AOT files. We are actively reviewing your submission and will update this shortly.


Last updated: Mar 23 2026 at 16:19 UTC