---
id: CVE-2026-54786
aliases:
  - RUSTSEC-2026-0182
  - GHSA-3p27-qvp9-27qf
title: Leak in WASIp1 `fd_renumber` implementation
summary: Leak in WASIp1 `fd_renumber` implementation
severity: none
vendor: wasmtime-wasi
product: wasmtime-wasi
ecosystem: rust
affected:
  - 'wasmtime-wasi >= 45.0.0, < 45.0.2'
patched:
  - wasmtime-wasi 45.0.2
published: '2026-06-15'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0182'
references:
  - url: 'https://crates.io/crates/wasmtime-wasi'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0182.html'
  - url: >-
      https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-3p27-qvp9-27qf
tags:
  - osv
  - rust
epss: 0.00367
epssPercentile: 0.27807
ingestedAt: '2026-07-09T18:56:37.355Z'
---

## Overview

This is an entry in the RustSec database for the Wasmtime security advisory
located at
https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-3p27-qvp9-27qf
For more information see the GitHub-hosted security advisory.

## Affected packages

- `wasmtime-wasi >= 45.0.0, < 45.0.2`

## Remediation

Upgrade to a patched release:

- `wasmtime-wasi 45.0.2`
