wasmtime vulnerabilities
CVEs whose affected-version data names the wasmtime package (pip, rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
9 CVEsRSS
RUSTSEC-2026-0269NoneFilesystem sandbox escape when paths or symlinks contain trailing slashes
Filesystem sandbox escape when paths or symlinks contain trailing slashes
RUSTSEC-2026-0268NoneGuest controlled-size host heap allocation through WASIp3 streams
Guest controlled-size host heap allocation through WASIp3 streams
RUSTSEC-2026-0223NonePreemption and traps during bulk operations enable breaking internal VM state
Preemption and traps during bulk operations enable breaking internal VM state
RUSTSEC-2026-0222Low· 3.8Stores can mix up type indices between engines
Stores can mix up type indices between engines
CVE-2026-44216High· 7.5Wasmtime is a runtime for WebAssembly
Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked on overflow. This overflow is possible to trigger, and thus…
CVE-2024-30266Medium· 5.5wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can l…
wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, w…
CVE-2023-41880Low· 2.2Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
CVE-2021-39216Medium· 6.3Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime
Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime
CVE-2021-32629High· 7.2Memory access due to code generation flaw in Cranelift module
Memory access due to code generation flaw in Cranelift module