RUSTSEC-2026-0322

Source
https://rustsec.org/advisories/RUSTSEC-2026-0322
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0322.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0322
Aliases
  • GHSA-gqmc-89g8-p25r
Published
2026-10-02T12:00:00Z
Modified
2026-10-02T20:30:02Z
Severity
  • 5.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Excessive allocated memory on the host when guests don't have stdio
Details

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-gqmc-89g8-p25r For more information see the GitHub-hosted security advisory.

Database specific
{
    "license":  "CC0-1.0"
}
References

Affected packages

crates.io / wasmtime-wasi

Package

Name
wasmtime-wasi
View open source insights on deps.dev
Purl
pkg:cargo/wasmtime-wasi

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
36.0.17
Introduced
37.0.0
Fixed
48.0.4
Introduced
49.0.0
Fixed
49.0.2

Ecosystem specific

{
    "affected_functions":  null,
    "affects":  {
        "arch":  [],
        "functions":  [],
        "os":  []
    }
}

Database specific

categories
[]
cvss
"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0322.json"