Vulnerability RUSTSEC-2026-0316
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 days ago
September 24, 2026 at 12:00 PM UTC
Dynamic record lifting can allocate beyond the hostcall fuel limit
0.0.0 - 36.0.15
0.0.0 - 36.0.15
Summary
Dynamic record lifting can allocate beyond the hostcall fuel limit
Details
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-jqpg-j7w6-42pr For more information see the GitHub-hosted security advisory.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
4 days ago
`call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification
47.0.0 - 48.0.2 RUSTSEC-2026-0315
47.0.0 - 48.0.2 RUSTSEC-2026-0315
Unknown
1 month ago
Guest controlled-size host heap allocation through WASIp3 streams
46.0.0 - 46.0.2 RUSTSEC-2026-0268
46.0.0 - 46.0.2 RUSTSEC-2026-0268
Unknown
1 month ago
Filesystem sandbox escape when paths or symlinks contain trailing slashes
0.0.0 - 24.0.12 RUSTSEC-2026-0269
0.0.0 - 24.0.12 RUSTSEC-2026-0269
Low Risk
1 month ago
Stores can mix up type indices between engines
0.0.0 - 24.0.11 RUSTSEC-2026-0222
0.0.0 - 24.0.11 RUSTSEC-2026-0222
Unknown
1 month ago
Preemption and traps during bulk operations enable breaking internal VM state
46.0.0 - 46.0.1 RUSTSEC-2026-0223
46.0.0 - 46.0.1 RUSTSEC-2026-0223
Impacted packages
Timeline
Published
4 days ago
September 24, 2026 at 12:00 PM UTC
Fixed (48.0.3)
4 days ago
September 24, 2026 at 06:58 PM UTC
Fixed (36.0.16)
4 days ago
September 24, 2026 at 07:10 PM UTC
Fixed (49.0.1)
4 days ago
September 24, 2026 at 07:19 PM UTC
Last Modified
2 hours ago
September 29, 2026 at 07:45 AM UTC