Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wasmtime — Vulnerabilities & Security Advisories 45

All 45 CVE vulnerabilities found in wasmtime, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for Bytecode Alliance's wasmtime. It collects reported flaws across all versions of the Rust-based WebAssembly runtime, covering advisories published from 2020 through the present. Readers can track the vendor’s response to each advisory, understand common weakness classes such as integer overflow or memory corruption, and review the product’s full vulnerability history without navigating between disparate databases. The dataset includes confirmed bugs, their severity ratings, and remediation status, enabling developers to assess risk for their specific deployment. No marketing language is used; the focus remains on factual disclosure and actionable security insights.

Vendor: bytecodealliance

CVE ID Title CVSS Severity Published
CVE-2023-30624 Wasmtime has Undefined Behavior in Rust runtime functions CWE-758 3.9 Low 2023-04-27
CVE-2023-26489 Guest-controlled out-of-bounds read/write on x86_64 in wasmtime CWE-125 10.0 Critical 2023-03-08
CVE-2023-27477 Wasmtime 安全漏洞 CWE-193 3.1 Low 2023-03-08
CVE-2022-39394 wasmtime_trap_code C API function has out of bounds write vulnerability CWE-787 3.8 Low 2022-11-10
CVE-2022-39392 Wasmtime vulnerable to out of bounds read/write with zero-memory-pages configuration CWE-119 5.9 Medium 2022-11-10
CVE-2022-39393 Wasmtime vulnerable to data leakage between instances in the pooling allocator CWE-226 8.6 High 2022-11-10
CVE-2022-31169 Cranelift vulnerable to miscompilation of constant values in division on AArch64 CWE-682 5.9 Medium 2022-07-21
CVE-2022-31146 Use After Free in Wasmtime CWE-416 6.4 Medium 2022-07-20
CVE-2022-31104 Miscompilation of `i8x16.swizzle` and `select` with v128 inputs in Wasmtime CWE-682 4.8 Medium 2022-06-27
CVE-2022-24791 Use after free in Wasmtime CWE-416 8.1 High 2022-03-31
CVE-2022-23636 Invalid drop of partially-initialized instances in wasmtime CWE-824 5.1 Medium 2022-02-16
CVE-2021-39218 Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime CWE-590 6.3 Medium 2021-09-17
CVE-2021-39219 Wrong type for `Linker`-define functions when used across two `Engine`s CWE-843 6.3 Medium 2021-09-17
CVE-2021-39216 Use after free passing `externref`s to Wasm in Wasmtime CWE-416 6.3 Medium 2021-09-17
CVE-2021-32629 Memory access due to code generation flaw in Cranelift module CWE-788 7.2 High 2021-05-24

All 45 known CVE vulnerabilities affecting wasmtime with full Chinese analysis, references, and POCs where available.