Reachable assertion in Wasmtime - CVE-2025-62711
Published: October 28, 2025
Wasmtime
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion within implementation of component-model related host-to-wasm trampolines. A remote user can create a specially crafted component that will cause the host to crash once called by the application.