---
id: CVE-2026-8257
title: A vulnerability was detected in WebAssembly Binaryen up to 117
summary: >-
  A vulnerability was detected in WebAssembly Binaryen up to 117. This issue
  affects the function IRBuilder::makeBrOn of the file
  src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a
  manipulation results in reachable ass…
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-617
vendor: webassembly
product: binaryen
affected:
  - binaryen <= 117
published: '2026-05-11'
updated: '2026-07-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8257'
references:
  - url: >-
      https://github.com/HackC0der/CVE-Repos/blob/main/wasm-binaryen/Assertion_Failure_isRef_wasm_Type_getHeapType_commit_3ef8d19
    label: cna@vuldb.com
  - url: 'https://github.com/WebAssembly/binaryen/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/WebAssembly/binaryen/commit/1251efbc1ea471c1311d2726b2bbe061ff2a291c
    label: cna@vuldb.com
  - url: 'https://github.com/WebAssembly/binaryen/issues/8633'
    label: cna@vuldb.com
  - url: 'https://github.com/WebAssembly/binaryen/pull/8635'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/809552'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362554'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362554/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00189
epssPercentile: 0.07552
ingestedAt: '2026-07-23T20:19:18.298Z'
---

## Overview

A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion. The attack needs to be approached locally. The exploit is now public and may be used. The patch is named 1251efbc1ea471c1311d2726b2bbe061ff2a291c. It is suggested to install a patch to address this issue.

## Affected

- `binaryen <= 117`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
