Improper Validation of Specified Type of Input in Wasmtime - #VU153228
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper validation of tag types in WebAssembly component validation when processing an invalid component that instantiates a core module importing a WebAssembly tag. A remote user can provide a component with a mis-typed tag import to cause a denial of service.
The WebAssembly exceptions proposal must be enabled, and user interaction is required.