---
id: CVE-2026-44216
title: Wasmtime is a runtime for WebAssembly
summary: >-
  Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and
  44.0.1, Wasmtime's allocation logic for a WebAssembly table contained checked
  arithmetic which panicked on overflow. This overflow is possible to trigger,
  and thus…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
  - CWE-190
vendor: bytecodealliance
product: wasmtime
affected:
  - 'wasmtime >= 30.0.0, < 36.0.8'
  - 'wasmtime >= 37.0.0, < 43.0.2'
  - wasmtime = 44.0.0
patched:
  - wasmtime 43.0.2
published: '2026-05-14'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44216'
references:
  - url: >-
      https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-p8xm-42r7-89xg
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:38187'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-44216'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2477467'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44216.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.00581
epssPercentile: 0.45402
ingestedAt: '2026-07-13T13:27:17.972Z'
---

## Overview

Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked on overflow. This overflow is possible to trigger, and thus panic, when a table with an extremely large size is allocated. This is possible with the WebAssembly memory64 proposal where tables can have sizes in the 64-bit range as opposed to the previous 32-bit range which would not overflow. The panic happens when attempting to create a very large table, such as when instantiating a WebAssembly module or component. This vulnerability is fixed in 36.0.8, 43.0.2, and 44.0.1.

## Affected

- `wasmtime >= 30.0.0, < 36.0.8`
- `wasmtime >= 37.0.0, < 43.0.2`
- `wasmtime = 44.0.0`

## Remediation

Upgrade past the affected range:

- `wasmtime 43.0.2`
