Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-2hw9-mc66-jc2q
  • crates.io/wasmtime
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state 9 hours ago
  • Fix available
  • Severity - 2.0 (Low)
CVE-2026-104855
  • github.com/bytecodealliance/wasmtime
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state 14 hours ago
  • Fix available
  • Severity - 2.0 (Low)
RUSTSEC-2026-0320
  • crates.io/wasmtime-wasi-http
Wasmtime wasi:http implementation panics with a zero timeout supplied 20 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0321
  • crates.io/wasmtime-wasi
WASI preview 0 implementation of `poll_oneoff` circumvents fuel consumption 20 hours ago
  • Fix available
  • Severity - 4.0 (Medium)
RUSTSEC-2026-0322
  • crates.io/wasmtime-wasi
Excessive allocated memory on the host when guests don't have stdio 20 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0323
  • crates.io/wasmtime-wasi
fd_readdir copies uninitialized struct padding into guest memory 20 hours ago
  • Fix available
  • Severity - 2.1 (Low)
RUSTSEC-2026-0324
  • crates.io/wasmtime-wasi
Guest can panic host through filesystem timestamp before the epoch on wasip3 20 hours ago
  • Fix available
  • Severity - 6.2 (Medium)
RUSTSEC-2026-0325
  • crates.io/wasmtime
Mis-typed WebAssembly tag imports can lead to GC heap corruption 20 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0326
  • crates.io/wasmtime
Rooting for GC values live across `try_call` may be missing, causing GC heap corruption 20 hours ago
  • Fix available
  • Severity - 5.7 (Medium)
RUSTSEC-2026-0327
  • crates.io/wasmtime
Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow 20 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
RUSTSEC-2026-0313
  • crates.io/wasmtime-wasi-http
Outgoing HTTP body write allows guest-driven host memory exhaustion 24 Sep
  • Fix available
  • Severity - 6.2 (Medium)
RUSTSEC-2026-0314
  • crates.io/wasmtime-wasi
Guest can panic host through filesystem datetime overflow 24 Sep
  • Fix available
  • Severity - 6.2 (Medium)
RUSTSEC-2026-0315
  • crates.io/wasmtime
`call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification 24 Sep
  • Fix available
  • Severity - 5.7 (Medium)
RUSTSEC-2026-0316
  • crates.io/wasmtime
Dynamic record lifting can allocate beyond the hostcall fuel limit 24 Sep
  • Fix available
  • Severity - 1.0 (Low)
CLEANSTART-2026-WJ40608
  • CleanStart/shadowsocks-rust
  • CleanStart/wasmtime
  • CleanStart/ztunnel-fips
Security fix for ghsa-434x-w66g-qw3r applied in: shadowsocks-rust 1.24.0-r0, wasmtime 40.0.0-r0, ztunnel-fips 1.26.8-r1, ztunnel-fips 1.27.6-r0, ztunnel-fips 1.28.4-r0, ztunnel-fips 1.29.0-r0 18 Sep
  • Fix available
CLEANSTART-2026-SI85644
  • CleanStart/wasmtime
  • CleanStart/ztunnel-fips
Security fix for ghsa-cq8v-f236-94qc applied in: wasmtime 40.0.0-r0, ztunnel-fips 1.27.8-r3, ztunnel-fips 1.28.5-r1, ztunnel-fips 1.28.7-r0, ztunnel-fips 1.29.1-r1, ztunnel-fips 1.30.0-r0 18 Sep
  • Fix available