VendorsBytecode Alliancewasmtime43.0.0
Vulnerabilities

Bytecode Alliance wasmtime 43.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-34987
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
Published 2026-04-09 · Analyzed
9.9EPSS 0.005
CVE-2026-34971
Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
Published 2026-04-09 · Modified
9.0EPSS 0.004
CVE-2026-35186
Wasmtime has an improperly masked return value from `table.grow` with Winch compiler backend
Published 2026-04-09 · Analyzed
7.5EPSS 0.004
CVE-2026-34988
Wasmtime leaks data between pooling allocator instances
Published 2026-04-09 · Analyzed
6.3EPSS 0.003
CVE-2026-35195
Wasmtime has an out-of-bounds write or crash when transcoding component model strings
Published 2026-04-09 · Analyzed
6.1EPSS 0.003
CVE-2026-34983
Wasmtime has a use-after-free bug after cloning `wasmtime::Linker`
Published 2026-04-09 · Analyzed
5.0EPSS 0.001