Uncontrolled Memory Allocation in Wasmtime - #VU144567
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to memory allocation with excessive size value in WASIp3 file and HTTP streams when writing to streams with a guest-specified-length buffer. A remote user can provide stream data with a guest-controlled length to cause a denial of service.
WASIp3 was not enabled by default in versions prior to 46.0.0. User interaction is required.