Resource exhaustion in Wasmtime - #VU153033
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper fuel accounting in the Cranelift backend when compiling guests containing `call_ref` callsites or calls within `try_table` catch paths. A remote user can execute a guest containing these opcodes to cause a denial of service.
Fuel consumption must be enabled, and user interaction is required.