CVE-2026-34971
Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
Summary
Remediation
Upgrade to the fixed version using your package manager.
cargo update -p wasmtime --precise 42.0.2
cargo update -p wasmtime --precise 36.0.7
cargo update -p wasmtime --precise 43.0.1
After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.
Affected Packages (3)
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 7.8 score means for each attack dimension.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
References
Frequently Asked Questions
- What is CVE-2026-34971?
- Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 7.8/10).
- How do I check if my project is affected by CVE-2026-34971?
- CVE-2026-34971 affects wasmtime. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-34971 and 200,000+ other known vulnerabilities.
Severity & Exploitability
High exploitability or significant impact. Prioritize remediation within days.
Also Known As
Related CVEs
- CVE-2026-34987CRITICAL
Wasmtime with Winch compiler backend may allow a sandbox-escaping memory access
- CVE-2026-34941MEDIUM
Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding
- CVE-2026-35186MEDIUM
Improperly masked return value from `table.grow` with Winch compiler backend
- CVE-2026-27572MEDIUM
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance
- CVE-2026-35195MEDIUM
Wasmtime has out-of-bounds write or crash when transcoding component model strings
- CVE-2026-27204MEDIUM
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
- CVE-2026-35186MEDIUM
Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend
- CVE-2024-51745LOW
Wasmtime doesn't fully sandbox all the Windows device filenames
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies