RUSTSEC-2026-0223

Source
https://rustsec.org/advisories/RUSTSEC-2026-0223
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0223.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0223
Aliases
  • GHSA-2hw9-mc66-jc2q
Published
2026-07-31T12:00:00Z
Modified
2026-07-31T16:45:04.187944627Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Preemption and traps during bulk operations enable breaking internal VM state
Details

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-2hw9-mc66-jc2q For more information see the GitHub-hosted security advisory.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / wasmtime

Package

Affected ranges

Type
SEMVER
Events
Introduced
46.0.0
Fixed
46.0.2
Introduced
47.0.0
Fixed
47.0.3

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "functions": [],
        "os": [],
        "arch": []
    }
}

Database specific

source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0223.json"
informational
null
cvss
"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"
categories
[]