📦 Wasmtime

by Bytecodealliance

🔍 What is Wasmtime?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-51745

CRITICAL CVSS 10.0 Nov 5, 2024

This vulnerability in Wasmtime's Windows filesystem sandbox allows untrusted WebAssembly programs to bypass device access restrictions by using superscript digits in special device filenames (e.g., CO...

CVE-2023-26489

CRITICAL CVSS 9.9 Mar 8, 2023

A memory corruption vulnerability in Wasmtime's Cranelift code generator allows WebAssembly modules to read/write memory beyond their allocated bounds. This affects x86_64 systems running vulnerable W...

CVE-2026-27195

HIGH CVSS 7.5 Feb 24, 2026

A bug in Wasmtime's async component model implementation causes a panic when call_async futures are dropped before completion and then called again on the same component instance. This affects Wasmtim...

CVE-2026-27572

HIGH CVSS 7.5 Feb 24, 2026

This vulnerability in Wasmtime's WASI HTTP implementation causes denial of service when excessive HTTP headers are processed. The runtime panics instead of gracefully handling the condition, allowing ...