Allocation of Resources Without Limits or Throttling in Wasmtime - #VU153226
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the SinkOutputStream write-zeros method when handling write-zeros operations from guests without configured stdout or stderr streams. A remote user can trigger an unbounded write-zeros operation to cause a denial of service.
Only embeddings without configured stdout or stderr streams are affected.