RUSTSEC-2026-0314Medium· 6.2▾ SunlitGuest can panic host through filesystem datetime overflow
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-j2g9-4prp-pf6h For more information see the GitHub-hosted security advisory.
wasmtime-wasi >= 49.0.0, < 49.0.1Upgrade to a patched release:
wasmtime-wasi 49.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-58494Medium· 6.5WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
CVE-2026-54786NoneLeak in WASIp1 `fd_renumber` implementation
CVE-2026-47261High· 7.5wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction