CVE-2025-62711Low· 3.1▾ SunlitWasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which when called in a specific way, would crash the host with a segfault or assert failure. Wasmtime 38.0.3 has been released and is patched to fix this issue. There are no workarounds.
wasmtime >= 38.0.0, < 38.0.3Upgrade past the affected range:
wasmtime 38.0.3Connected by shared product, vendor, weakness, or advisory.
RUSTSEC-2026-0316NoneDynamic record lifting can allocate beyond the hostcall fuel limit
RUSTSEC-2026-0315Medium· 5.7`call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification
RUSTSEC-2026-0269NoneFilesystem sandbox escape when paths or symlinks contain trailing slashes
RUSTSEC-2026-0268NoneGuest controlled-size host heap allocation through WASIp3 streams
RUSTSEC-2026-0223NonePreemption and traps during bulk operations enable breaking internal VM state
RUSTSEC-2026-0222Low· 3.8Stores can mix up type indices between engines