Vulnerability RUSTSEC-2026-0315
Medium Risk
MEDIUM RISK
CVSS Score: 5.7
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 days ago
September 24, 2026 at 12:00 PM UTC
`call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification
47.0.0 - 48.0.2
47.0.0 - 48.0.2
Summary
`call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification
Details
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-m63x-6p34-q65x For more information see the GitHub-hosted security advisory.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
4 days ago
Dynamic record lifting can allocate beyond the hostcall fuel limit
0.0.0 - 36.0.15 RUSTSEC-2026-0316
0.0.0 - 36.0.15 RUSTSEC-2026-0316
Unknown
1 month ago
Guest controlled-size host heap allocation through WASIp3 streams
46.0.0 - 46.0.2 RUSTSEC-2026-0268
46.0.0 - 46.0.2 RUSTSEC-2026-0268
Unknown
1 month ago
Filesystem sandbox escape when paths or symlinks contain trailing slashes
0.0.0 - 24.0.12 RUSTSEC-2026-0269
0.0.0 - 24.0.12 RUSTSEC-2026-0269
Low Risk
1 month ago
Stores can mix up type indices between engines
0.0.0 - 24.0.11 RUSTSEC-2026-0222
0.0.0 - 24.0.11 RUSTSEC-2026-0222
Unknown
1 month ago
Preemption and traps during bulk operations enable breaking internal VM state
46.0.0 - 46.0.1 RUSTSEC-2026-0223
46.0.0 - 46.0.1 RUSTSEC-2026-0223
Impacted packages
Timeline
Published
4 days ago
September 24, 2026 at 12:00 PM UTC
Fixed (48.0.3)
4 days ago
September 24, 2026 at 06:58 PM UTC
Fixed (49.0.1)
4 days ago
September 24, 2026 at 07:19 PM UTC
Last Modified
2 hours ago
September 29, 2026 at 07:45 AM UTC