wasmtime-wasi vulnerabilities
CVEs whose affected-version data names the wasmtime-wasi package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-58494Medium· 6.5WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
▾ Sunlitwasmtime-wasi · wasmtime-wasiEPSS 0.17%via OSV
CVE-2026-54786NoneLeak in WASIp1 `fd_renumber` implementation
Leak in WASIp1 `fd_renumber` implementation
▾ Sunlitwasmtime-wasi · wasmtime-wasiEPSS 0.22%via OSV
CVE-2026-47261High· 7.5wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
▾ Twilightwasmtime-wasi · wasmtime-wasiEPSS 0.36%via OSV