wasmtime Security Analysis
wasmtime has 28 known security vulnerabilities in crates.io (Rust). Upgrade to version 43.0.1 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 43.0.1
Upgrading to 43.0.1 or later resolves all 28 known vulnerabilities in wasmtime. Update Cargo.toml: wasmtime = "43.0.1"
Is wasmtime in your project?
Check if you're affected and upgrade to 43.0.1 to stay secure.
Vulnerabilities
28 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-34987 Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access | CRITICAL | 43.0.0 | 36.0.7, 42.0.2, 43.0.1 |
| CVE-2023-26489 wasmtime vulnerable to guest-controlled out-of-bounds read/write on x86_64 | CRITICAL | All versions | 4.0.1, 5.0.1, 6.0.1 |
| CVE-2026-34987 Wasmtime with Winch compiler backend may allow a sandbox-escaping memory access | CRITICAL | All versions | 36.0.7, 42.0.2, 43.0.1 |
| CVE-2026-34971 Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift | CRITICAL | All versions | 36.0.7, 42.0.2, 43.0.1 |
| CVE-2023-26489 Guest-controlled out-of-bounds read/write on x86\_64 | CRITICAL | All versions | 4.0.1, 5.0.1, 6.0.1 |
| CVE-2026-34971 Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift | CRITICAL | 43.0.0 | 36.0.7, 42.0.2, 43.0.1 |
| CVE-2022-39393 Wasmtime may have data leakage between instances in the pooling allocator | HIGH | All versions | 2.0.2, 1.0.2 |
| CVE-2022-39393 Data leakage between instances in the pooling allocator | HIGH | All versions | 1.0.2, 2.0.2 |
| CVE-2026-35195 Out-of-bounds write or crash when transcoding component model strings | HIGH | All versions | 24.0.7, 36.0.7, 42.0.2 (+1 more) |
| CVE-2022-39392 Bug in Wasmtime implementation of pooling instance allocator | HIGH | All versions | 1.0.2, 2.0.2 |
| CVE-2026-34941 Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding | MEDIUM | 43.0.0 | 24.0.7, 36.0.7, 42.0.2 (+1 more) |
| CVE-2026-34943 Wasmtime has a possible panic when lifting `flags` component value | MEDIUM | 43.0.0 | 24.0.7, 36.0.7, 42.0.2 (+1 more) |
| CVE-2026-34946 Wasmtime has host panic when Winch compiler executes `table.fill` | MEDIUM | 43.0.0 | 36.0.7, 42.0.2, 43.0.1 |
| CVE-2026-35195 Wasmtime has out-of-bounds write or crash when transcoding component model strings | MEDIUM | 43.0.0 | 24.0.7, 36.0.7, 42.0.2 (+1 more) |
| CVE-2026-34942 Wasmtime: Panic when transcoding misaligned utf-16 strings | MEDIUM | 43.0.0 | 24.0.7, 36.0.7, 42.0.2 (+1 more) |
| CVE-2026-27572 Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance | MEDIUM | All versions | 24.0.6, 36.0.6, 40.0.4 |
| CVE-2026-27204 Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion | MEDIUM | All versions | 24.0.6, 36.0.6, 40.0.4 |
| CVE-2026-35186 Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend | MEDIUM | 43.0.0 | 36.0.7, 42.0.2, 43.0.1 |
| CVE-2026-34942 Panic when transcoding misaligned component model UTF-16 strings | MEDIUM | All versions | 24.0.7, 36.0.7, 42.0.2 (+1 more) |
| CVE-2026-27204 Guest-controlled resource exhaustion in WASI implementations | MEDIUM | All versions | 24.0.6, 36.0.6, 40.0.4 (+1 more) |
| CVE-2026-27572 Panic adding excessive fields to a `wasi:http/types.fields` instance | MEDIUM | All versions | 24.0.6, 36.0.6, 40.0.4 (+1 more) |
| CVE-2026-34944 Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64 | MEDIUM | 43.0.0 | 24.0.7, 36.0.7, 42.0.2 (+1 more) |
| CVE-2026-35186 Improperly masked return value from `table.grow` with Winch compiler backend | MEDIUM | All versions | 36.0.7, 42.0.2, 43.0.1 |
| CVE-2026-27195 Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future | MEDIUM | All versions | 40.0.4, 41.0.4 |
| CVE-2024-47763 wasmtime has a runtime crash when combining tail calls with trapping imports | MEDIUM | All versions | 21.0.2, 22.0.1, 23.0.3 (+2 more) |
| CVE-2026-34941 Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding | MEDIUM | All versions | 24.0.7, 36.0.7, 42.0.2 (+1 more) |
| CVE-2026-34945 Wasmtime has host data leakage with 64-bit tables and Winch | LOW | 43.0.0 | 36.0.7, 42.0.2, 43.0.1 |
| CVE-2024-51745 Wasmtime doesn't fully sandbox all the Windows device filenames | LOW | 26.0.0 | 24.0.2, 25.0.3, 26.0.1 |
About This Data
Vulnerability data for wasmtime is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related crates.io (Rust) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of wasmtime.