SB2026100311 - Multiple vulnerabilities in Wasmtime



SB2026100311 - Multiple vulnerabilities in Wasmtime

Published: October 3, 2026

Security Bulletin ID SB2026100311
CSH Severity
High
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 13% Low 88%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 vulnerabilities.


1) Improper control of a resource through its lifetime (CVE-ID: N/A)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper rooting of garbage-collected references in Wasmtime compiler handling of `try_call` when compiling a Wasm module. A remote user can provide a crafted Wasm module to cause a denial of service.

Exploitation requires GC and exception support, and the callee must trigger garbage collection while a GC reference is live across `try_call`.


2) Resource exhaustion (CVE-ID: N/A)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing fuel consumption checks in the WASI preview 0 implementation of poll_oneoff when processing subscriptions. A remote attacker can invoke poll_oneoff with many subscriptions to cause a denial of service.

Exploitation requires WASI preview 0 support to be enabled.


3) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the SinkOutputStream write-zeros method when handling write-zeros operations from guests without configured stdout or stderr streams. A remote user can trigger an unbounded write-zeros operation to cause a denial of service.

Only embeddings without configured stdout or stderr streams are affected.


4) Improper Check for Unusual or Exceptional Conditions (CVE-ID: N/A)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper handling of a zero timeout in the wasi:http implementation when processing a between-bytes-timeout request option with a zero timeout. A remote user can specify a zero timeout to cause a denial of service.

Only use of the wasmtime-wasi-http crate with the default-send-request Cargo feature enabled is affected.


5) Improper Validation of Specified Type of Input (CVE-ID: N/A)

CWE-ID: CWE-1287 - Improper Validation of Specified Type of Input

CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper validation of tag types in WebAssembly component validation when processing an invalid component that instantiates a core module importing a WebAssembly tag. A remote user can provide a component with a mis-typed tag import to cause a denial of service.

The WebAssembly exceptions proposal must be enabled, and user interaction is required.


6) Stack-based buffer overflow (CVE-ID: N/A)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary host code.

The vulnerability exists due to a stack-based buffer overflow in async-lifted callback handling when processing a crafted component with an invalid callback return signature. A remote attacker can provide a crafted component to execute arbitrary host code.

Exploitation requires the component-model-async feature to be enabled.


7) Improper Check for Unusual or Exceptional Conditions (CVE-ID: N/A)

CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an improper check for unusual or exceptional conditions in the WASIp3 filesystem timestamp conversion in wasmtime-wasi on Unix hosts when processing a guest-supplied timestamp before the Unix epoch. A remote attacker can specify a pre-epoch filesystem timestamp through the WASIp3 set-times or set-times-at methods to cause a denial of service.

Only WASIp3 configurations on Unix that provide the guest with a mutable preopened descriptor are affected.


8) Use of uninitialized resource (CVE-ID: N/A)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to use of an uninitialized resource in the WASIp1 `fd_readdir` implementation when listing entries from a preopened directory. A remote user can invoke `fd_readdir` to disclose sensitive information.

The affected guest must have access to a preopened directory, and user interaction is required.


Remediation

Install update from vendor's website.