Stack-based buffer overflow in Wasmtime - #VU153229
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary host code.
The vulnerability exists due to a stack-based buffer overflow in async-lifted callback handling when processing a crafted component with an invalid callback return signature. A remote attacker can provide a crafted component to execute arbitrary host code.
Exploitation requires the component-model-async feature to be enabled.