PT-2026-31684 · Bytecode Alliance · Wasmtime
Published
2026-04-09
·
Updated
2026-05-06
·
CVE-2026-34943
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Wasmtime versions prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1
Description
Wasmtime, a runtime for WebAssembly, may experience a panic when a flags-typed component model value is lifted with the
Val type. This occurs if bits are set outside the expected flags, leading to a guest-controlled panic within the host, which is considered a denial-of-service vector. This issue specifically affects flags-typed values within a WIT interface and the lifting process into Val, not the flags! macro.Recommendations
Update to Wasmtime version 24.0.7, 36.0.7, 42.0.2, or 43.0.1.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wasmtime