Allocation of Resources Without Limits or Throttling in Wasmtime - #VU153031
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to failure to enforce write allowances in wasmtime-wasi-http outgoing HTTP body write handling when a guest supplies a buffer larger than the allowance returned by check-write. A remote attacker can invoke check-write and pass an oversized buffer to write to cause a denial of service.