Security: bytecodealliance/wasmtime
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Stores can mix up type indices between enginesGHSA-hgjw-h833-99q9 published
Jul 31, 2026 by alexcrichtonLow -
Preemption and traps during bulk operations enable breaking internal VM stateGHSA-2hw9-mc66-jc2q published
Jul 31, 2026 by alexcrichtonLow -
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destinationGHSA-4ch3-9j33-3pmj published
Jun 24, 2026 by pchickeyModerate -
Leak in WASIp1 `fd_renumber` implementationGHSA-3p27-qvp9-27qf published
Jun 15, 2026 by alexcrichtonLow -
WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restrictionGHSA-2r75-cxrj-cmph published
May 21, 2026 by pchickeyHigh -
Panic when allocating a table exceeding the size of the host's address spaceGHSA-p8xm-42r7-89xg published
Apr 30, 2026 by alexcrichtonModerate -
Out-of-bounds write or crash when transcoding component model stringsGHSA-394w-hwhg-8vgm published
Apr 9, 2026 by alexcrichtonModerate -
Use-after-free bug after cloning `wasmtime::Linker`GHSA-hfr4-7c6c-48w2 published
Apr 9, 2026 by alexcrichtonLow -
Data leakage between pooling allocator instancesGHSA-6wgr-89rj-399p published
Apr 9, 2026 by alexcrichtonLow -
Host data leakage with 64-bit tables and WinchGHSA-m9w2-8782-2946 published
Apr 9, 2026 by alexcrichtonLow