Improper control of a resource through its lifetime in Wasmtime - #VU153224
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper rooting of garbage-collected references in Wasmtime compiler handling of `try_call` when compiling a Wasm module. A remote user can provide a crafted Wasm module to cause a denial of service.
Exploitation requires GC and exception support, and the callee must trigger garbage collection while a GC reference is live across `try_call`.