Vulnerability RUSTSEC-2026-0314
Medium Risk
MEDIUM RISK
CVSS Score: 6.2
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 days ago
September 24, 2026 at 12:00 PM UTC
Guest can panic host through filesystem datetime overflow
0.2.0 - 36.0.15
0.2.0 - 36.0.15
Summary
Guest can panic host through filesystem datetime overflow
Details
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-j2g9-4prp-pf6h For more information see the GitHub-hosted security advisory.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
1 month ago
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
0.2.0 - 24.0.9 and 25.0.0 - 36.0.10 and 37.0.0 - 44.0.2 and 45.0.0 - 45.0.1 GHSA-3p27-qvp9-27qf
0.2.0 - 24.0.9 and 25.0.0 - 36.0.10 and 37.0.0 - 44.0.2 and 45.0.0 - 45.0.1 GHSA-3p27-qvp9-27qf
Medium Risk
3 months ago
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
0.2.0 - 24.0.10 RUSTSEC-2026-0188
0.2.0 - 24.0.10 RUSTSEC-2026-0188
Unknown
3 months ago
Leak in WASIp1 `fd_renumber` implementation
0.2.0 - 24.0.9 RUSTSEC-2026-0182
0.2.0 - 24.0.9 RUSTSEC-2026-0182
High Risk
3 months ago
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
0.2.0 - 24.0.8 and 25.0.0 - 36.0.9 and 37.0.0 - 44.0.1 GHSA-2r75-cxrj-cmph
0.2.0 - 24.0.8 and 25.0.0 - 36.0.9 and 37.0.0 - 44.0.1 GHSA-2r75-cxrj-cmph
High Risk
4 months ago
WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
0.2.0 - 24.0.8 RUSTSEC-2026-0149
0.2.0 - 24.0.8 RUSTSEC-2026-0149
Impacted packages
Timeline
Published
4 days ago
September 24, 2026 at 12:00 PM UTC
Fixed (48.0.3)
4 days ago
September 24, 2026 at 06:58 PM UTC
Fixed (36.0.16)
4 days ago
September 24, 2026 at 07:10 PM UTC
Fixed (49.0.1)
4 days ago
September 24, 2026 at 07:19 PM UTC
Last Modified
2 hours ago
September 29, 2026 at 07:45 AM UTC