目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1310 CNY

100%

bytecodealliance 厂商漏洞列表 / CVE 中文分析 49

bytecodealliance 厂商相关 49 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Bytecode Alliance 致力于通过 WebAssembly 技术实现安全、高效的跨平台代码执行,核心项目包括 Wasmtime 运行时及 WasmEdge。其历史漏洞多涉及内存安全缺陷,如缓冲区溢出与空指针解引用,部分严重问题可导致远程代码执行。近期关注点在于其沙箱隔离机制的有效性验证及组件模型中的权限控制。作为开源基础设施,其安全性直接影响依赖该技术的众多应用生态,需持续监控其补丁更新与内存安全规范落实情况。

41 件の結果 / 49フィルターをクリア
CVE IDタイトルCVSS深刻度公開日
CVE-2026-44216 Wasmtime: Panic when allocating a table exceeding the size of the host's address space — wasmtimeCWE-770--2026-05-14
CVE-2026-35195 Wasmtime has an out-of-bounds write or crash when transcoding component model strings — wasmtimeCWE-787 9.9AICriticalAI2026-04-09
CVE-2026-35186 Wasmtime has an improperly masked return value from `table.grow` with Winch compiler backend — wasmtimeCWE-789 9.1AICriticalAI2026-04-09
CVE-2026-34988 Wasmtime leaks data between pooling allocator instances — wasmtimeCWE-119 7.5AIHighAI2026-04-09
CVE-2026-34987 Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access — wasmtimeCWE-125 6.3AIMediumAI2026-04-09
CVE-2026-34983 Wasmtime has a use-after-free bug after cloning `wasmtime::Linker` — wasmtimeCWE-416 7.5AIHighAI2026-04-09
CVE-2026-34971 Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift — wasmtimeCWE-125 9.1AICriticalAI2026-04-09
CVE-2026-34946 Wasmtime's host panics when Winch compiler executes `table.fill` — wasmtimeCWE-670 7.7AIHighAI2026-04-09
CVE-2026-34945 Wasmtime leaks host data with 64-bit tables and Winch — wasmtimeCWE-681 6.5AIMediumAI2026-04-09
CVE-2026-34944 Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64 — wasmtimeCWE-248 7.5AIHighAI2026-04-09
CVE-2026-34943 Wasmtime panics when lifting `flags` component value — wasmtimeCWE-248 7.5AIHighAI2026-04-09
CVE-2026-34942 Wasmtime panics when transcoding misaligned utf-16 strings — wasmtimeCWE-129 7.7AIHighAI2026-04-09
CVE-2026-34941 Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding — wasmtimeCWE-125 6.5AIMediumAI2026-04-09
CVE-2026-27572 Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance — wasmtimeCWE-770 7.5 -2026-02-24
CVE-2026-27204 Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion — wasmtimeCWE-400 6.5 -2026-02-24
CVE-2026-27195 Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future — wasmtimeCWE-755 6.8 -2026-02-24
CVE-2026-24116 Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64 — wasmtimeCWE-125 7.5AIHighAI2026-01-27
CVE-2025-64345 Wasmtime provides unsound API access to a WebAssembly shared linear memory — wasmtimeCWE-362 1.8 Low2025-11-12
CVE-2025-62711 Wasmtime vulnerable to segfault when using component resources — wasmtimeCWE-755 7.5 -2025-10-24
CVE-2025-61670 Wasmtime has memory leak in C API with `externref` and `anyref` types — wasmtimeCWE-772 7.5AIHighAI2025-10-07
CVE-2025-53901 Wasmtime has host panic with `fd_renumber` WASIp1 function — wasmtimeCWE-672 3.5 Low2025-07-18
CVE-2024-51745 Wasmtime doesn't fully sandbox all the Windows device filenames — wasmtimeCWE-67 8.2AIHighAI2024-11-05
CVE-2024-47813 Wasmtime race condition could lead to WebAssembly control-flow integrity and type safety violations — wasmtimeCWE-367 2.9 Low2024-10-09
CVE-2024-47763 Wasmtime runtime crash when combining tail calls with trapping imports — wasmtimeCWE-670 5.5 Medium2024-10-09
CVE-2024-30266 Wasmtime vulnerable to panic when using a dropped extenref-typed element segment — wasmtimeCWE-843 3.3 Low2024-04-04
CVE-2023-41880 Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64 — wasmtimeCWE-193 2.2 Low2023-09-15
CVE-2023-30624 Wasmtime has Undefined Behavior in Rust runtime functions — wasmtimeCWE-758 3.9 Low2023-04-27
CVE-2023-26489 Guest-controlled out-of-bounds read/write on x86_64 in wasmtime — wasmtimeCWE-125 10.0 Critical2023-03-08
CVE-2023-27477 Wasmtime 安全漏洞 — wasmtimeCWE-193 3.1 Low2023-03-08
CVE-2022-39393 Wasmtime vulnerable to data leakage between instances in the pooling allocator — wasmtimeCWE-226 8.6 High2022-11-10

本页汇总了 bytecodealliance 厂商截至目前公开的全部 49 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。