{"id":"CVE-2024-27529","aliases":["PYSEC-2024-305"],"url":"https://o3.security/vulnerability/CVE-2024-27529","summary":"wasm3 uncontrolled memory allocation vulnerability","details":"wasm3 at commit 139076a contains a memory leak in the Read_utf8 function.","published":"2024-11-09T00:30:42Z","modified":"2026-09-10T03:50:20.646148431Z","cvss":{"score":8.4,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00266,"percentile":0.18371,"asOf":"2026-08-03"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"wasm3","fixedVersion":null},{"ecosystem":"PyPI","name":"pywasm3","fixedVersion":null},{"ecosystem":"SwiftURL","name":"github.com/shareup/wasm-interpreter-apple","fixedVersion":null}],"fix":{"url":"https://github.com/wasm3/wasm3/pull/490","label":"wasm3/wasm3#490"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27529"},{"type":"WEB","url":"https://github.com/wasm3/wasm3/issues/462"},{"type":"WEB","url":"https://github.com/wasm3/wasm3/pull/490"},{"type":"WEB","url":"https://github.com/wasm3/wasm3/commit/526c1251b64e6e9fdc0d40c768ae46cd20338594"},{"type":"WEB","url":"https://gist.github.com/haruki3hhh/ac70bd83b9c0ed1de6289d818488da78"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pywasm3/PYSEC-2024-305.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:20.646148431Z"}}