Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wasmtime — Vulnerabilities & Security Advisories 45

All 45 CVE vulnerabilities found in wasmtime, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for Bytecode Alliance's wasmtime. It collects reported flaws across all versions of the Rust-based WebAssembly runtime, covering advisories published from 2020 through the present. Readers can track the vendor’s response to each advisory, understand common weakness classes such as integer overflow or memory corruption, and review the product’s full vulnerability history without navigating between disparate databases. The dataset includes confirmed bugs, their severity ratings, and remediation status, enabling developers to assess risk for their specific deployment. No marketing language is used; the focus remains on factual disclosure and actionable security insights.

Vendor: bytecodealliance

CVE ID Title CVSS Severity Published
CVE-2026-104855 Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state CWE-362 2.0 Low 2026-10-02
CVE-2026-58494 Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination CWE-281 6.5 Medium 2026-07-08
CVE-2026-54786 Wasmtime: Leak in WASIp1 `fd_renumber` implementation CWE-772 - - 2026-07-01
CVE-2026-47261 Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction CWE-284 7.5 High 2026-06-15
CVE-2026-44216 Wasmtime: Panic when allocating a table exceeding the size of the host's address space CWE-770 5.9 Medium 2026-05-14
CVE-2026-35195 Wasmtime has an out-of-bounds write or crash when transcoding component model strings CWE-787 9.9AI Critical AI 2026-04-09
CVE-2026-35186 Wasmtime has an improperly masked return value from `table.grow` with Winch compiler backend CWE-789 9.1AI Critical AI 2026-04-09
CVE-2026-34988 Wasmtime leaks data between pooling allocator instances CWE-119 7.5AI High AI 2026-04-09
CVE-2026-34987 Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access CWE-125 6.3AI Medium AI 2026-04-09
CVE-2026-34983 Wasmtime has a use-after-free bug after cloning `wasmtime::Linker` CWE-416 7.5AI High AI 2026-04-09
CVE-2026-34971 Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift CWE-125 9.1AI Critical AI 2026-04-09
CVE-2026-34946 Wasmtime's host panics when Winch compiler executes `table.fill` CWE-670 7.7AI High AI 2026-04-09
CVE-2026-34945 Wasmtime leaks host data with 64-bit tables and Winch CWE-681 6.5AI Medium AI 2026-04-09
CVE-2026-34944 Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64 CWE-248 7.5AI High AI 2026-04-09
CVE-2026-34943 Wasmtime panics when lifting `flags` component value CWE-248 7.5AI High AI 2026-04-09
CVE-2026-34942 Wasmtime panics when transcoding misaligned utf-16 strings CWE-129 7.7AI High AI 2026-04-09
CVE-2026-34941 Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding CWE-125 6.5AI Medium AI 2026-04-09
CVE-2026-27572 Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance CWE-770 7.5 - 2026-02-24
CVE-2026-27204 Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion CWE-400 6.5 - 2026-02-24
CVE-2026-27195 Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future CWE-755 6.8 - 2026-02-24
CVE-2026-24116 Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64 CWE-125 7.5AI High AI 2026-01-27
CVE-2025-64345 Wasmtime provides unsound API access to a WebAssembly shared linear memory CWE-362 1.8 Low 2025-11-12
CVE-2025-62711 Wasmtime vulnerable to segfault when using component resources CWE-755 7.5 - 2025-10-24
CVE-2025-61670 Wasmtime has memory leak in C API with `externref` and `anyref` types CWE-772 7.5AI High AI 2025-10-07
CVE-2025-53901 Wasmtime has host panic with `fd_renumber` WASIp1 function CWE-672 3.5 Low 2025-07-18
CVE-2024-51745 Wasmtime doesn't fully sandbox all the Windows device filenames CWE-67 8.2AI High AI 2024-11-05
CVE-2024-47813 Wasmtime race condition could lead to WebAssembly control-flow integrity and type safety violations CWE-367 2.9 Low 2024-10-09
CVE-2024-47763 Wasmtime runtime crash when combining tail calls with trapping imports CWE-670 5.5 Medium 2024-10-09
CVE-2024-30266 Wasmtime vulnerable to panic when using a dropped extenref-typed element segment CWE-843 3.3 Low 2024-04-04
CVE-2023-41880 Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64 CWE-193 2.2 Low 2023-09-15

All 45 known CVE vulnerabilities affecting wasmtime with full Chinese analysis, references, and POCs where available.