CVE-2026-8257: WebAssembly Binaryen BrOn wasm-ir-builder.cpp makeBrOn assertion
A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion. The attack needs to be approached locally. The exploit is now public and may be used. The patch is named 1251efbc1ea471c1311d2726b2bbe061ff2a291c. It is suggested to install a patch to address this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WebAssembly Binaryen BrOn Parserto a version that resolves this vulnerability.Patch 1251efbc1ea471c1311d2726b2bbe061ff2a291c - Compensating control
Approach the attack locally (limit exposure so exploitation is not possible remotely).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8257?
CVE-2026-8257 has been assigned a moderate severity level due to potential impacts on application stability.
How do I fix CVE-2026-8257?
To fix CVE-2026-8257, upgrade WebAssembly Binaryen to version 118 or later.
What vulnerability does CVE-2026-8257 describe?
CVE-2026-8257 describes an assertion failure in the IRBuilder::makeBrOn function of the wasm-ir-builder.cpp file in WebAssembly Binaryen.
Which versions of WebAssembly Binaryen are affected by CVE-2026-8257?
CVE-2026-8257 affects WebAssembly Binaryen versions up to and including 117.
What components are involved in CVE-2026-8257?
CVE-2026-8257 involves the BrOn Parser component of the WebAssembly Binaryen.