Wasmtime

Bytecodealliance · 45 CVEs

CVE-2026-104855
LOW

Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state

Oct 2, 2026

CVE-2026-58494
MEDIUM

Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination

Jul 8, 2026

CVE-2026-54786
LOW

Wasmtime: Leak in WASIp1 `fd_renumber` implementation

Jul 1, 2026

CVE-2026-47261
HIGH

Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction

Jun 15, 2026

CVE-2026-44216
MEDIUM

Wasmtime: Panic when allocating a table exceeding the size of the host's address space

May 14, 2026

CVE-2026-35195
MEDIUM

Wasmtime has an out-of-bounds write or crash when transcoding component model strings

Apr 9, 2026

CVE-2026-35186
MEDIUM

Wasmtime has an improperly masked return value from `table.grow` with Winch compiler backend

Apr 9, 2026

CVE-2026-34988
LOW

Wasmtime leaks data between pooling allocator instances

Apr 9, 2026

CVE-2026-34987
CRITICAL

Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access

Apr 9, 2026

CVE-2026-34983
LOW

Wasmtime has a use-after-free bug after cloning `wasmtime::Linker`

Apr 9, 2026

CVE-2026-34971
CRITICAL

Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift

Apr 9, 2026

CVE-2026-34946
MEDIUM

Wasmtime's host panics when Winch compiler executes `table.fill`

Apr 9, 2026

CVE-2026-34945
LOW

Wasmtime leaks host data with 64-bit tables and Winch

Apr 9, 2026

CVE-2026-34944
MEDIUM

Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64

Apr 9, 2026

CVE-2026-34943
MEDIUM

Wasmtime panics when lifting `flags` component value

Apr 9, 2026

CVE-2026-34942
MEDIUM

Wasmtime panics when transcoding misaligned utf-16 strings

Apr 9, 2026

CVE-2026-34941
MEDIUM

Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding

Apr 9, 2026

CVE-2026-27572
MEDIUM

Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance

Feb 24, 2026

CVE-2026-27204
MEDIUM

Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion

Feb 24, 2026

CVE-2026-27195
MEDIUM

Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future

Feb 24, 2026

CVE-2026-24116
MEDIUM

Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64

Jan 27, 2026

CVE-2025-64345
LOW

Wasmtime provides unsound API access to a WebAssembly shared linear memory

Nov 12, 2025

CVE-2025-62711
LOW

Wasmtime vulnerable to segfault when using component resources

Oct 24, 2025

CVE-2025-61670
LOW

Wasmtime has memory leak in C API with `externref` and `anyref` types

Oct 7, 2025

CVE-2025-53901
LOW

Wasmtime has host panic with `fd_renumber` WASIp1 function

Jul 18, 2025

Showing 1 to 25 of 45 CVEs