Where
-Infinity
0

Vendor Risk Score

See how bytecodealliance compares to other vendors in security performance

View Risk Score →

bytecodealliance Wasmtime RustWasmtime: Leak in WASIp1 `fd_renumber` implementation

Risk 26
Severity
2.3
First published (updated )

rust/wasmtime-wasiWasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction

Risk 43
Severity
7.5
First published (updated )

bytecodealliance Wasmtime RustWasmtime: Panic when allocating a table exceeding the size of the host's address space

Risk 43
Severity
5.9
First published (updated )

rust/wasmtimeWasmtime has an out-of-bounds write or crash when transcoding component model strings

Risk 51
Severity
6.1
First published (updated )

rust/wasmtimeWasmtime has an improperly masked return value from `table.grow` with Winch compiler backend

Risk 43
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

rust/wasmtimeWasmtime leaks data between pooling allocator instances

Risk 37
Severity
2.3
First published (updated )

rust/wasmtimeWasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access

Risk 82
Severity
9
First published (updated )

rust/wasmtimeWasmtime has a use-after-free bug after cloning `wasmtime::Linker`

Risk 29
Severity
1
First published (updated )

rust/wasmtimeWasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift

Risk 76
Severity
9
First published (updated )

rust/wasmtimeWasmtime's host panics when Winch compiler executes `table.fill`

Risk 43
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

rust/wasmtimeWasmtime leaks host data with 64-bit tables and Winch

Risk 38
Severity
2.3
First published (updated )

rust/wasmtimeWasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64

Risk 33
Severity
4.1
First published (updated )

rust/wasmtimeWasmtime panics when lifting `flags` component value

Risk 43
Severity
5.6
First published (updated )

rust/wasmtimeWasmtime panics when transcoding misaligned utf-16 strings

Risk 38
Severity
5.9
First published (updated )

rust/wasmtimeWasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding

Risk 60
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

rust/wasmtimeWasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance

Risk 31
Severity
7.5
EPSS
0.07%
First published (updated )

rust/wasmtimeWasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion

Risk 27
Severity
6.9
EPSS
0.07%
First published (updated )

rust/wasmtimeWasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future

Risk 31
Severity
7.5
EPSS
0.06%
First published (updated )

rust/wasmtimeWasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64

Risk 23
Severity
5.5
EPSS
0.01%
First published (updated )

WebAssembly Micro RuntimeWebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode

Risk 67
Severity
7.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

WebAssembly Micro RuntimeWebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instruction

Risk 31
Severity
5.5
First published (updated )

Wasmtime WasmtimeWasmtime vulnerable to segfault when using component resources

Risk 17
Severity
3.1
First published (updated )

bytecodealliance Wasmtime RustWasmtime has memory leak in C API with `externref` and `anyref` types

Risk 18
Severity
1
First published (updated )

Microsoft cbl2 fluent-bit 3.0.6-3WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode

Risk 27
Severity
5.3
First published (updated )

WebAssembly Micro Runtime iwasmWebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified

Risk 33
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

rust/wasmtimeWasmtime has host panic with `fd_renumber` WASIp1 function

Risk 19
Severity
3.5
First published (updated )

WebAssembly Micro Runtime iwasmiwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi feature

Risk 40
Severity
7
EPSS
0.01%
First published (updated )

bytecodealliance Webassembly Micro RuntimeAn issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows …

Risk 77
Severity
8.8
First published (updated )

wasm-micro-runtime WebAssembly Micro RuntimeNull Pointer Dereference

Risk 43
Severity
7.5
First published (updated )

bytecodealliance Wasmtime RustWasmtime doesn't fully sandbox all the Windows device filenames

Risk 90
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203