Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Capstone-engine
Capstone-engine capstone |
|
| Vendors & Products |
Capstone-engine
Capstone-engine capstone |
Fri, 14 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large but well-formed `br_table` instruction, the WASM decoder accumulates the immediate length in a wider local variable but returns it through a `uint16_t` instruction-size path. When the encoded instruction length is exactly 65,536 bytes, the size wraps to zero and `cs_disasm()` can repeatedly decode the same instruction without advancing. For larger lengths, `cs_disasm_iter()` advances into the middle of the `br_table` payload and decodes target bytes as subsequent instructions. This is an availability and parser-integrity issue. Version 6.0.0-Alpha9 patches the issue. | |
| Title | Capstone WASM `br_table` instruction-size truncation can cause no-progress disassembly and parser desynchronization | |
| Weaknesses | CWE-197 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-14T17:49:36.804Z
Reserved: 2026-05-28T14:33:01.180Z
Link: CVE-2026-49263
No data.
Status : Received
Published: 2026-08-14T18:17:30.643
Modified: 2026-08-14T18:17:30.643
Link: CVE-2026-49263
No data.
OpenCVE Enrichment
Updated: 2026-08-14T19:30:04Z
-
CWE-197
Numeric Truncation Error