CVE-2025-66627: Critical Use-After-Free in Wasmi's Linear Memory
(updated )
A use-after-free vulnerability has been discovered in the linear memory implementation of Wasmi. This issue can be triggered by a WebAssembly module under certain memory growth conditions, potentially leading to memory corruption, information disclosure, or code execution.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-66627 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →