Resource exhaustion in Wasmtime - #VU153225
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing fuel consumption checks in the WASI preview 0 implementation of poll_oneoff when processing subscriptions. A remote attacker can invoke poll_oneoff with many subscriptions to cause a denial of service.
Exploitation requires WASI preview 0 support to be enabled.