wasmtime-wasi
A lightweight WebAssembly runtime that is fast, secure, and standards-compliant
Activity
- Latest release
- 3d ago
- Total releases
- 219
- Cadence
- ~daily
- Last 12 months
- 69
Reach
- Downloads
- 10.6M
- Stars
- 18.6k
Details
- License
- Apache-2.0 WITH LLVM-exception
- First release
- Aug 21, 2019
| Version | Released | |
|---|---|---|
48.0.2
patch
|
48.0.2
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
36.0.15
patch
|
36.0.15
patch
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
49.0.0-rc.1
pre
|
49.0.0-rc.1
pre
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
48.0.1
patch
|
48.0.1
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
36.0.14
patch
|
36.0.14
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
46.0.3
patch
|
46.0.3
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
47.0.4
patch
|
47.0.4
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
24.0.13
patch
|
24.0.13
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
48.0.0
major
|
48.0.0
major
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
47.0.3
patch
|
47.0.3
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
46.0.2
patch
|
46.0.2
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
36.0.13
patch
|
36.0.13
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
24.0.12
patch
|
24.0.12
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
47.0.2
patch
|
47.0.2
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
47.0.1
patch
|
47.0.1
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
47.0.0
major
|
47.0.0
major
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
36.0.12
patch
|
36.0.12
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
45.0.3
patch
|
45.0.3
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
46.0.1
patch
|
46.0.1
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
24.0.11
patch
|
24.0.11
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
46.0.0
major
1 CVE
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev |
46.0.0
major
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
24.0.10
patch
1 CVE
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev |
24.0.10
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
44.0.3
patch
1 CVE
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev |
44.0.3
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
45.0.2
patch
1 CVE
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev |
45.0.2
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
36.0.11
patch
1 CVE
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev |
36.0.11
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
45.0.1
patch
2 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev |
45.0.1
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
44.0.2
patch
2 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev |
44.0.2
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
36.0.10
patch
2 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev |
36.0.10
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
45.0.0
major
2 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev |
45.0.0
major
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
24.0.9
patch
2 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev |
24.0.9
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
36.0.9
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
36.0.9
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
36.0.8
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
36.0.8
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
43.0.2
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
43.0.2
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
44.0.1
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
44.0.1
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
24.0.8
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
24.0.8
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
44.0.0
major
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
44.0.0
major
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
42.0.2
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
42.0.2
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
43.0.1
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
43.0.1
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
36.0.7
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
36.0.7
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
24.0.7
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
24.0.7
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
43.0.0
major
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
43.0.0
major
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
42.0.1
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
42.0.1
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
41.0.4
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
41.0.4
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
40.0.4
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
40.0.4
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
42.0.0
major
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
42.0.0
major
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
24.0.6
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
24.0.6
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
36.0.6
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
36.0.6
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
41.0.3
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
41.0.3
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
41.0.2
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
41.0.2
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
40.0.3
patch
3 CVEs
CVE-2026-54786
GHSA-3p27-qvp9-27qf
RUSTSEC-2026-0182
Aug 26, 2026
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Low
Network
Low
Low
None
ImpactWasmtime's native implementation of WASIp1 suffers from a leak in the This bug only affects the native implementation of WASIp1. This means that only runtimes which load core wasm modules and expose PatchesWasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 have been released which fix this issue. WorkaroundsThere are no workarounds for this issue and hosts are recommended to update. Fixed in
24.0.10
36.0.11
44.0.3
45.0.2
References
Updated Aug 26, 2026 · Source: OSV.dev
CVE-2026-58494
RUSTSEC-2026-0188
GHSA-4ch3-9j33-3pmj
Jun 24, 2026
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
6.5
/ 10
Medium
Local
Low
Low
None
Changed
None
High
None
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory. Fixed in
24.0.11
36.0.12
45.0.3
46.0.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-47261
GHSA-2r75-cxrj-cmph
RUSTSEC-2026-0149
Jun 05, 2026
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
SummaryIn
The root cause is that the clause that considered The bug in
and the single line fix is:
Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the
In particular, the Wasmtime project's Fixed in
24.0.9
36.0.10
44.0.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
40.0.3
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|