Vulnerability RUSTSEC-2026-0222
Low Risk
LOW RISK
CVSS Score: 3.8
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
1 month ago
July 31, 2026 at 12:00 PM UTC
Stores can mix up type indices between engines
0.0.0 - 24.0.11
0.0.0 - 24.0.11
Summary
Stores can mix up type indices between engines
Details
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-hgjw-h833-99q9 For more information see the GitHub-hosted security advisory.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
4 days ago
`call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification
47.0.0 - 48.0.2 RUSTSEC-2026-0315
47.0.0 - 48.0.2 RUSTSEC-2026-0315
Unknown
4 days ago
Dynamic record lifting can allocate beyond the hostcall fuel limit
0.0.0 - 36.0.15 RUSTSEC-2026-0316
0.0.0 - 36.0.15 RUSTSEC-2026-0316
Unknown
1 month ago
Guest controlled-size host heap allocation through WASIp3 streams
46.0.0 - 46.0.2 RUSTSEC-2026-0268
46.0.0 - 46.0.2 RUSTSEC-2026-0268
Unknown
1 month ago
Filesystem sandbox escape when paths or symlinks contain trailing slashes
0.0.0 - 24.0.12 RUSTSEC-2026-0269
0.0.0 - 24.0.12 RUSTSEC-2026-0269
Unknown
1 month ago
Preemption and traps during bulk operations enable breaking internal VM state
46.0.0 - 46.0.1 RUSTSEC-2026-0223
46.0.0 - 46.0.1 RUSTSEC-2026-0223
Impacted packages
Timeline
Published
1 month ago
July 31, 2026 at 12:00 PM UTC
Fixed (24.0.12)
1 month ago
July 31, 2026 at 03:29 PM UTC
Fixed (36.0.13)
1 month ago
July 31, 2026 at 03:41 PM UTC
Fixed (46.0.2)
1 month ago
July 31, 2026 at 04:15 PM UTC
Fixed (47.0.3)
1 month ago
July 31, 2026 at 04:18 PM UTC
Last Modified
1 month ago
July 31, 2026 at 04:45 PM UTC