wasmtime has 7 CVEs on record between 2021 and 2026. 4 were published in the last 90 days. The median CVSS is 4.7 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.7
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Products
- wasmtime 7
Worst active — by depth score
CVE-2021-39216Medium· 6.3Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime 35CVE-2024-30266Medium· 5.5wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can l…30RUSTSEC-2026-0222Low· 3.8Stores can mix up type indices between engines21CVE-2023-41880Low· 2.2Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_6412RUSTSEC-2026-0269NoneFilesystem sandbox escape when paths or symlinks contain trailing slashes3
wasmtime vulnerabilities
CVEs affecting wasmtime, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
RUSTSEC-2026-0269NoneFilesystem sandbox escape when paths or symlinks contain trailing slashes
Filesystem sandbox escape when paths or symlinks contain trailing slashes
RUSTSEC-2026-0268NoneGuest controlled-size host heap allocation through WASIp3 streams
Guest controlled-size host heap allocation through WASIp3 streams
RUSTSEC-2026-0223NonePreemption and traps during bulk operations enable breaking internal VM state
Preemption and traps during bulk operations enable breaking internal VM state
RUSTSEC-2026-0222Low· 3.8Stores can mix up type indices between engines
Stores can mix up type indices between engines
CVE-2024-30266Medium· 5.5wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can l…
wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, w…
CVE-2023-41880Low· 2.2Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
CVE-2021-39216Medium· 6.3Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime
Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime