Missing Release of Resource after Effective Lifetime in Wasmtime - CVE-2025-61670
Published: April 23, 2026
Wasmtime
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper resource management in the Wasmtime C/C++ API when handling externref or anyref values. A remote user can trigger memory leaks to cause a denial of service.
The issue affects the C/C++ API, while the Rust crate is unaffected. User interaction is required.