Resource exhaustion in Wasmtime - #VU153032
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to inadequate resource accounting in the dynamically typed Val API when loading a value returned by a guest. A remote user can return a value that causes excessive host memory allocations to cause a denial of service.
Only hosts using the Val API are affected; hosts using bindgen! or other statically typed APIs are unaffected.