RUSTSEC-2026-0321Medium· 4.0▾ SunlitWASI preview 0 implementation of `poll_oneoff` circumvents fuel consumption
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-j366-h8gg-77pm For more information see the GitHub-hosted security advisory.
wasmtime-wasi >= 49.0.0, < 49.0.2Upgrade to a patched release:
wasmtime-wasi 49.0.2Connected by shared product, vendor, weakness, or advisory.
RUSTSEC-2026-0324Medium· 6.2Guest can panic host through filesystem timestamp before the epoch on wasip3
RUSTSEC-2026-0322NoneExcessive allocated memory on the host when guests don't have stdio
RUSTSEC-2026-0323Nonefd_readdir copies uninitialized struct padding into guest memory
RUSTSEC-2026-0314Medium· 6.2Guest can panic host through filesystem datetime overflow
CVE-2026-58494Medium· 6.5WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination