CVE-2026-34988Improper Restriction of Operations within the Bounds of a Memory Buffer in Wasmtime

Severity
2.3LOWNVD
EPSS
0.0%
top 98.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 9

Description

Wasmtime is a runtime for WebAssembly. From 28.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of its pooling allocator contains a bug where in certain configurations the contents of linear memory can be leaked from one instance to the next. The implementation of resetting the virtual memory permissions for linear memory used the wrong predicate to determine if resetting was necessary, where the compilation process used a different predicate. This divergence meant that the po

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N

Affected Packages2 packages

crates.iobytecodealliance/wasmtime0.0.0-036.0.7+3
CVEListV5bytecodealliance/wasmtime>= 28.0.0, < 36.0.7, >= 37.0.0, < 42.0.2, >= 43.0.0, < 44.0.1+2

🔴Vulnerability Details

4
OSV
Data leakage between pooling allocator instances2026-04-09
OSV
Wasmtime has data leakage between pooling allocator instances2026-04-09
GHSA
Wasmtime has data leakage between pooling allocator instances2026-04-09
VulDB
bytecodealliance wasmtime up to 36.0.6/42.0.1/44.0.0 memory_guard_size memory corruption (GHSA-6wgr-89rj-399p)2026-04-09

📋Vendor Advisories

1
Red Hat
wasmtime: Wasmtime: Information disclosure due to improper memory handling in pooling allocator2026-04-09

🕵️Threat Intelligence

73
Wiz
CVE-2026-34944 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-5745 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-28808 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-5442 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2026-5443 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

2
Bugzilla
CVE-2026-34988 tree-sitter: Wasmtime: Information disclosure due to improper memory handling in pooling allocator [fedora-all]2026-04-09
Bugzilla
CVE-2026-34988 wasmtime: Wasmtime: Information disclosure due to improper memory handling in pooling allocator2026-04-09