VulnSea

wasmtime has 7 CVEs on record between 2021 and 2026. 4 were published in the last 90 days. The median CVSS is 4.7 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
4.7
Publish → KEV
Last 90 days
4 prev 0

Products

  • wasmtime 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

wasmtime vulnerabilities

CVEs affecting wasmtime, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

RUSTSEC-2026-0269None
1mo ago

Filesystem sandbox escape when paths or symlinks contain trailing slashes

Filesystem sandbox escape when paths or symlinks contain trailing slashes

Sunlitwasmtime · wasmtimevia OSV
RUSTSEC-2026-0268None
1mo ago

Guest controlled-size host heap allocation through WASIp3 streams

Guest controlled-size host heap allocation through WASIp3 streams

Sunlitwasmtime · wasmtimevia OSV
RUSTSEC-2026-0223None
1mo ago

Preemption and traps during bulk operations enable breaking internal VM state

Preemption and traps during bulk operations enable breaking internal VM state

Sunlitwasmtime · wasmtimevia OSV
RUSTSEC-2026-0222Low· 3.8
1mo ago

Stores can mix up type indices between engines

Stores can mix up type indices between engines

Sunlitwasmtime · wasmtimevia OSV
CVE-2024-30266Medium· 5.5
2y ago

wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can l…

wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, w…

Sunlitwasmtime · wasmtimeEPSS 0.32%via OSV
CVE-2023-41880Low· 2.2
3y ago

Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64

Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64

Sunlitwasmtime · wasmtimeEPSS 0.67%via OSV
CVE-2021-39216Medium· 6.3
5y ago

Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime

Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime

Sunlitwasmtime · wasmtimeEPSS 0.31%via OSV
wasmtime vulnerabilities (CVEs) · VulnSea