VulnSea

wasmtime vulnerabilities

CVEs whose affected-version data names the wasmtime package (pip, rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

RUSTSEC-2026-0269None
1mo ago

Filesystem sandbox escape when paths or symlinks contain trailing slashes

Filesystem sandbox escape when paths or symlinks contain trailing slashes

Sunlitwasmtime · wasmtimevia OSV
RUSTSEC-2026-0268None
1mo ago

Guest controlled-size host heap allocation through WASIp3 streams

Guest controlled-size host heap allocation through WASIp3 streams

Sunlitwasmtime · wasmtimevia OSV
RUSTSEC-2026-0223None
1mo ago

Preemption and traps during bulk operations enable breaking internal VM state

Preemption and traps during bulk operations enable breaking internal VM state

Sunlitwasmtime · wasmtimevia OSV
RUSTSEC-2026-0222Low· 3.8
1mo ago

Stores can mix up type indices between engines

Stores can mix up type indices between engines

Sunlitwasmtime · wasmtimevia OSV
CVE-2026-44216High· 7.5
4mo ago

Wasmtime is a runtime for WebAssembly

Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked on overflow. This overflow is possible to trigger, and thus…

Twilightbytecodealliance · wasmtimeEPSS 0.32%via NVD
CVE-2024-30266Medium· 5.5
2y ago

wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can l…

wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, w…

Sunlitwasmtime · wasmtimeEPSS 0.32%via OSV
CVE-2023-41880Low· 2.2
3y ago

Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64

Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64

Sunlitwasmtime · wasmtimeEPSS 0.67%via OSV
CVE-2021-39216Medium· 6.3
5y ago

Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime

Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime

Sunlitwasmtime · wasmtimeEPSS 0.31%via OSV
CVE-2021-32629High· 7.2
5y ago

Memory access due to code generation flaw in Cranelift module

Memory access due to code generation flaw in Cranelift module

Twilightcranelift-codegen · cranelift-codegenEPSS 0.46%via OSV
wasmtime vulnerabilities (CVEs) · VulnSea