freenode

← digests

Ladybird Wasm RCE fix, Next.js CVE backport question

Web Platform2026-09-07

Ladybird closed a web-reachable code execution flaw in its WebAssembly ESM path. A Next.js user separately pressed for clarity on whether an older release covers a listed CVE.

Ladybird fixes web-reachable RCE in Wasm ESM integration

A dangling FunctionType reference in Ladybird browser's WebAssembly ESM integration enabled web-reachable code execution, filed as CVE-2026-58592 against ladybirdbrowser/ladybird. The report describes the loader defect and notes the issue is fixed in a merged pull request. Browser and Wasm toolchain developers should treat the remediation as material because the attack surface is reachable from ordinary web content.

Next.js 15.5.21 patch status for CVE-2026-64643 remains unclear

A single participant in the vercel/next.js repository asked whether version 15.5.21 addresses CVE-2026-64643 after the related advisory named only v16 as fixed. No further confirmation appears in the short thread. Operators still on the 15.x line need an explicit statement before assuming the release closes the vulnerability.