---
id: RUSTSEC-2026-0313
aliases:
  - GHSA-c9gc-w9vx-w86p
title: Outgoing HTTP body write allows guest-driven host memory exhaustion
summary: Outgoing HTTP body write allows guest-driven host memory exhaustion
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: wasmtime-wasi-http
product: wasmtime-wasi-http
ecosystem: rust
affected:
  - 'wasmtime-wasi-http >= 49.0.0, < 49.0.1'
patched:
  - wasmtime-wasi-http 49.0.1
published: '2026-09-24'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T07:45:02.372565508Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0313'
references:
  - url: 'https://crates.io/crates/wasmtime-wasi-http'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0313.html'
  - url: 'https://github.com/bytecodealliance/wasmtime/pull/14408'
tags:
  - osv
  - rust
ingestedAt: '2026-09-30T07:22:02.090Z'
---

## Overview

This is an entry in the RustSec database for the Wasmtime security advisory
located at
https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-c9gc-w9vx-w86p
For more information see the GitHub-hosted security advisory.

## Affected packages

- `wasmtime-wasi-http >= 49.0.0, < 49.0.1`

## Remediation

Upgrade to a patched release:

- `wasmtime-wasi-http 49.0.1`
