Bytecodealliance Wasmtime vulnerabilities
44 known vulnerabilities affecting bytecodealliance/wasmtime.
Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH16MEDIUM18LOW5
Vulnerabilities
Page 3 of 3
CVE-2025-61670P4LOWCVSS 3.3v37.0.0v37.0.1+1 more2025-10-07
CVE-2025-61670 [LOW] CWE-772 CVE-2025-61670: Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API
Wasmtime is a runtime for WebAssembly. Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the `anyref` or `externref` WebAssembly values. This is caused by a regression introduced during the development of 37.0.0 and all prior versions of Wasmtime are unaffected. If `anyref` or `externref` is not used in the C/C++ API
nvd
CVE-2025-62711P4LOWCVSS 3.1≥ 38.0.0, < 38.0.3v>= 38.0.0, < 38.0.32025-10-24
CVE-2025-62711 [LOW] CWE-755 CVE-2025-62711: Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation
Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which when called in a specific way, would crash the host with a segfault or assert failure. Wasmtime 38.0.3 has been relea
ghsanvdosv
CVE-2024-47813P4LOWCVSS 2.9v19.0.0v19.0.1+18 more2024-10-09
CVE-2024-47813 [LOW] CWE-367 CVE-2024-47813: Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `was
Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to a race condition, leading to panics and potentially type registry corruption. That registry corruption could, following an additional and particular sequence of
ghsanvdosv
CVE-2025-64345P4LOWCVSS 1.8v>= 38.0.1, < 38.0.4v>= 37.0.0, < 37.0.3+2 more2025-11-12
CVE-2025-64345 [LOW] CWE-362 CVE-2025-64345: Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, and 24.0.5, Wasmtime
Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, and 24.0.5, Wasmtime's Rust embedder API contains an unsound interaction where a WebAssembly shared linear memory could be viewed as a type which provides safe access to the host (Rust) to the contents of the linear memory. This is not sound for shared linear memories, whic
ghsanvdosv
← Previous3 / 3