Improper Check for Unusual or Exceptional Conditions in Wasmtime - #VU153227
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper handling of a zero timeout in the wasi:http implementation when processing a between-bytes-timeout request option with a zero timeout. A remote user can specify a zero timeout to cause a denial of service.
Only use of the wasmtime-wasi-http crate with the default-send-request Cargo feature enabled is affected.