wasmtime
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting wasmtimepage 1 of 1
- CVE-2021-32629HIGHCVSS 7.2EG 7.2✓ Fixed in 0.27.02021-05-24
vulnerable: 0.0.1 ... 0.9.0 (21 versions)
Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermediate representation into executable machine code. There is a bug in 0.73 of the Cranelift x64 backend that can create a …
- CVE-2021-39216MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.30.02021-09-17
vulnerable: 0.0.1 ... 0.9.0 (25 versions)
Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.19.0 and before version 0.30.0 there was a use-after-free bug when passing `externref`s from the host to guest Wasm content. To trigger the bug, you have…
- CVE-2021-39218MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.30.02021-09-17
vulnerable: 0.0.1 ... 0.9.0 (25 versions)
Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.26.0 and before version 0.30.0 is affected by a memory unsoundness vulnerability. There was an invalid free and out-of-bounds read and write bug when run…
- CVE-2021-39219MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.30.02021-09-17
vulnerable: 0.0.1 ... 0.9.0 (25 versions)
Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affected by a type confusion vulnerability. As a Rust library the `wasmtime` crate clearly marks which functions are safe and which are `unsafe`, …
- CVE-2024-47813LOWCVSS 2.9EG 2.92024-10-09
vulnerable: 0.0.1 ... 9.0.0 (68 versions)
Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to a race condition, leading to panics and potent…
- CVE-2026-34983MEDIUMCVSS 5.0EG 5.02026-04-09
vulnerable: 0.0.1 ... 9.0.0 (87 versions)
Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free bugs. This bug is not controllable by guest Wasm programs. It can only be triggered by a specific sequence of embedder…
Check whether wasmtime is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for wasmtime CVEs against the assets you own.
Start Free Scan →