#VU125757 Incorrect calculation in Wasmtime - CVE-2026-34946
Published: April 10, 2026
Wasmtime
Bytecode Alliance
Description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to incorrect table indexing in the Winch compiler when compiling the table.fill instruction. A remote user can compile a valid guest that uses table.fill to cause a denial of service.
User interaction is required to process the crafted guest.