RUSTSEC-2026-0324

Source
https://rustsec.org/advisories/RUSTSEC-2026-0324
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0324.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0324
Aliases
  • GHSA-mr2v-56j5-cmfc
Published
2026-10-02T12:00:00Z
Modified
2026-10-02T20:30:02Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Guest can panic host through filesystem timestamp before the epoch on wasip3
Details

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-mr2v-56j5-cmfc For more information see the GitHub-hosted security advisory.

Database specific
{
    "license":  "CC0-1.0"
}
References

Affected packages

crates.io / wasmtime-wasi

Package

Name
wasmtime-wasi
View open source insights on deps.dev
Purl
pkg:cargo/wasmtime-wasi

Affected ranges

Type
SEMVER
Events
Introduced
46.0.0
Fixed
48.0.4
Introduced
49.0.0
Fixed
49.0.2

Ecosystem specific

{
    "affected_functions":  null,
    "affects":  {
        "arch":  [],
        "functions":  [],
        "os":  []
    }
}

Database specific

categories
[]
cvss
"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0324.json"