PT-2026-31684 · Bytecode Alliance · Wasmtime

Published

2026-04-09

·

Updated

2026-05-06

·

CVE-2026-34943

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wasmtime versions prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1
Description Wasmtime, a runtime for WebAssembly, may experience a panic when a flags-typed component model value is lifted with the Val type. This occurs if bits are set outside the expected flags, leading to a guest-controlled panic within the host, which is considered a denial-of-service vector. This issue specifically affects flags-typed values within a WIT interface and the lifting process into Val, not the flags! macro.
Recommendations Update to Wasmtime version 24.0.7, 36.0.7, 42.0.2, or 43.0.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34943
GHSA-M758-WJHJ-P3JQ
OPENSUSE-SU-2026:10715-1
RUSTSEC-2026-0085

Affected Products

Wasmtime