PYSEC-2024-327

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/wasmtime/PYSEC-2024-327.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2024-327
Aliases
Published
2024-04-04T16:15:09.107Z
Modified
2026-07-13T07:26:38.201559381Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this panic. This vulnerability has been patched in version 19.0.1.

References

Affected packages

PyPI / wasmtime

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
19.0.0

Affected versions

0.*
0.0.1
0.0.2
0.9.0
0.11.0
0.12.0
0.15.0
0.15.1
0.16.0
0.16.1
0.17.0
0.18.0
0.18.1
0.18.2
0.19.0
0.20.0
0.21.0
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
0.27.0
0.28.0
0.28.1
0.29.0
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.38.0
0.39.1
0.40.0
1.*
1.0.0
1.0.1
2.*
2.0.0
3.*
3.0.0
4.*
4.0.0
5.*
5.0.0
6.*
6.0.0
7.*
7.0.0
8.*
8.0.0
8.0.1
9.*
9.0.0
10.*
10.0.0
10.0.1
11.*
11.0.0
12.*
12.0.0
13.*
13.0.0
13.0.1
13.0.2
14.*
14.0.0
15.*
15.0.0
16.*
16.0.0
17.*
17.0.0
17.0.1
18.*
18.0.0
18.0.2
19.*
19.0.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/wasmtime/PYSEC-2024-327.yaml"