SB2026100311 - Multiple vulnerabilities in Wasmtime
Published: October 3, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 vulnerabilities.
1) Improper control of a resource through its lifetime (CVE-ID: N/A)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper rooting of garbage-collected references in Wasmtime compiler handling of `try_call` when compiling a Wasm module. A remote user can provide a crafted Wasm module to cause a denial of service.
Exploitation requires GC and exception support, and the callee must trigger garbage collection while a GC reference is live across `try_call`.
2) Resource exhaustion (CVE-ID: N/A)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing fuel consumption checks in the WASI preview 0 implementation of poll_oneoff when processing subscriptions. A remote attacker can invoke poll_oneoff with many subscriptions to cause a denial of service.
Exploitation requires WASI preview 0 support to be enabled.
3) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the SinkOutputStream write-zeros method when handling write-zeros operations from guests without configured stdout or stderr streams. A remote user can trigger an unbounded write-zeros operation to cause a denial of service.
Only embeddings without configured stdout or stderr streams are affected.
4) Improper Check for Unusual or Exceptional Conditions (CVE-ID: N/A)
CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions
CVSSv4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper handling of a zero timeout in the wasi:http implementation when processing a between-bytes-timeout request option with a zero timeout. A remote user can specify a zero timeout to cause a denial of service.
Only use of the wasmtime-wasi-http crate with the default-send-request Cargo feature enabled is affected.
5) Improper Validation of Specified Type of Input (CVE-ID: N/A)
CWE-ID: CWE-1287 - Improper Validation of Specified Type of Input
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper validation of tag types in WebAssembly component validation when processing an invalid component that instantiates a core module importing a WebAssembly tag. A remote user can provide a component with a mis-typed tag import to cause a denial of service.
The WebAssembly exceptions proposal must be enabled, and user interaction is required.
6) Stack-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary host code.
The vulnerability exists due to a stack-based buffer overflow in async-lifted callback handling when processing a crafted component with an invalid callback return signature. A remote attacker can provide a crafted component to execute arbitrary host code.
Exploitation requires the component-model-async feature to be enabled.
7) Improper Check for Unusual or Exceptional Conditions (CVE-ID: N/A)
CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an improper check for unusual or exceptional conditions in the WASIp3 filesystem timestamp conversion in wasmtime-wasi on Unix hosts when processing a guest-supplied timestamp before the Unix epoch. A remote attacker can specify a pre-epoch filesystem timestamp through the WASIp3 set-times or set-times-at methods to cause a denial of service.
Only WASIp3 configurations on Unix that provide the guest with a mutable preopened descriptor are affected.
8) Use of uninitialized resource (CVE-ID: N/A)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to use of an uninitialized resource in the WASIp1 `fd_readdir` implementation when listing entries from a preopened directory. A remote user can invoke `fd_readdir` to disclose sensitive information.
The affected guest must have access to a preopened directory, and user interaction is required.
Remediation
Install update from vendor's website.
References
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-hw8m-q44c-ggrf
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-j366-h8gg-77pm
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-gqmc-89g8-p25r
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-w4qr-p94g-mjhv
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-cfhf-m2cr-62wj
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-32h6-97mm-8q3c
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-mr2v-56j5-cmfc
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-96f6-r43r-8c24