Loading...
Skip to main content
crates.io (Rust)

wasmtime Security Analysis

wasmtime has 28 known security vulnerabilities in crates.io (Rust). Upgrade to version 43.0.1 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

28 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 43.0.1

Upgrading to 43.0.1 or later resolves all 28 known vulnerabilities in wasmtime. Update Cargo.toml: wasmtime = "43.0.1"

Is wasmtime in your project?

Check if you're affected and upgrade to 43.0.1 to stay secure.

28
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

28 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-34987
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
CRITICAL
43.0.036.0.7, 42.0.2, 43.0.1
CVE-2023-26489
wasmtime vulnerable to guest-controlled out-of-bounds read/write on x86_64
CRITICAL
All versions4.0.1, 5.0.1, 6.0.1
CVE-2026-34987
Wasmtime with Winch compiler backend may allow a sandbox-escaping memory access
CRITICAL
All versions36.0.7, 42.0.2, 43.0.1
CVE-2026-34971
Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
CRITICAL
All versions36.0.7, 42.0.2, 43.0.1
CVE-2023-26489
Guest-controlled out-of-bounds read/write on x86\_64
CRITICAL
All versions4.0.1, 5.0.1, 6.0.1
CVE-2026-34971
Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
CRITICAL
43.0.036.0.7, 42.0.2, 43.0.1
CVE-2022-39393
Wasmtime may have data leakage between instances in the pooling allocator
HIGH
All versions2.0.2, 1.0.2
CVE-2022-39393
Data leakage between instances in the pooling allocator
HIGH
All versions1.0.2, 2.0.2
CVE-2026-35195
Out-of-bounds write or crash when transcoding component model strings
HIGH
All versions24.0.7, 36.0.7, 42.0.2 (+1 more)
CVE-2022-39392
Bug in Wasmtime implementation of pooling instance allocator
HIGH
All versions1.0.2, 2.0.2
CVE-2026-34941
Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding
MEDIUM
43.0.024.0.7, 36.0.7, 42.0.2 (+1 more)
CVE-2026-34943
Wasmtime has a possible panic when lifting `flags` component value
MEDIUM
43.0.024.0.7, 36.0.7, 42.0.2 (+1 more)
CVE-2026-34946
Wasmtime has host panic when Winch compiler executes `table.fill`
MEDIUM
43.0.036.0.7, 42.0.2, 43.0.1
CVE-2026-35195
Wasmtime has out-of-bounds write or crash when transcoding component model strings
MEDIUM
43.0.024.0.7, 36.0.7, 42.0.2 (+1 more)
CVE-2026-34942
Wasmtime: Panic when transcoding misaligned utf-16 strings
MEDIUM
43.0.024.0.7, 36.0.7, 42.0.2 (+1 more)
CVE-2026-27572
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance
MEDIUM
All versions24.0.6, 36.0.6, 40.0.4
CVE-2026-27204
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
MEDIUM
All versions24.0.6, 36.0.6, 40.0.4
CVE-2026-35186
Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend
MEDIUM
43.0.036.0.7, 42.0.2, 43.0.1
CVE-2026-34942
Panic when transcoding misaligned component model UTF-16 strings
MEDIUM
All versions24.0.7, 36.0.7, 42.0.2 (+1 more)
CVE-2026-27204
Guest-controlled resource exhaustion in WASI implementations
MEDIUM
All versions24.0.6, 36.0.6, 40.0.4 (+1 more)
CVE-2026-27572
Panic adding excessive fields to a `wasi:http/types.fields` instance
MEDIUM
All versions24.0.6, 36.0.6, 40.0.4 (+1 more)
CVE-2026-34944
Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64
MEDIUM
43.0.024.0.7, 36.0.7, 42.0.2 (+1 more)
CVE-2026-35186
Improperly masked return value from `table.grow` with Winch compiler backend
MEDIUM
All versions36.0.7, 42.0.2, 43.0.1
CVE-2026-27195
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
MEDIUM
All versions40.0.4, 41.0.4
CVE-2024-47763
wasmtime has a runtime crash when combining tail calls with trapping imports
MEDIUM
All versions21.0.2, 22.0.1, 23.0.3 (+2 more)
CVE-2026-34941
Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding
MEDIUM
All versions24.0.7, 36.0.7, 42.0.2 (+1 more)
CVE-2026-34945
Wasmtime has host data leakage with 64-bit tables and Winch
LOW
43.0.036.0.7, 42.0.2, 43.0.1
CVE-2024-51745
Wasmtime doesn't fully sandbox all the Windows device filenames
LOW
26.0.024.0.2, 25.0.3, 26.0.1

About This Data

Vulnerability data for wasmtime is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related crates.io (Rust) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of wasmtime.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed