Vulnerability RUSTSEC-2026-0322
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
12 hours ago
October 02, 2026 at 12:00 PM UTC
Excessive allocated memory on the host when guests don't have stdio
0.2.0 - 36.0.16
0.2.0 - 36.0.16
Summary
Excessive allocated memory on the host when guests don't have stdio
Details
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-gqmc-89g8-p25r For more information see the GitHub-hosted security advisory.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
12 hours ago
WASI preview 0 implementation of `poll_oneoff` circumvents fuel consumption
0.2.0 - 36.0.16 RUSTSEC-2026-0321
0.2.0 - 36.0.16 RUSTSEC-2026-0321
Unknown
12 hours ago
fd_readdir copies uninitialized struct padding into guest memory
0.2.0 - 36.0.16 RUSTSEC-2026-0323
0.2.0 - 36.0.16 RUSTSEC-2026-0323
Medium Risk
12 hours ago
Guest can panic host through filesystem timestamp before the epoch on wasip3
46.0.0 - 48.0.3 RUSTSEC-2026-0324
46.0.0 - 48.0.3 RUSTSEC-2026-0324
Medium Risk
8 days ago
Guest can panic host through filesystem datetime overflow
0.2.0 - 36.0.15 RUSTSEC-2026-0314
0.2.0 - 36.0.15 RUSTSEC-2026-0314
Medium Risk
1 month ago
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
0.2.0 - 24.0.9 and 25.0.0 - 36.0.10 and 37.0.0 - 44.0.2 and 45.0.0 - 45.0.1 GHSA-3p27-qvp9-27qf
0.2.0 - 24.0.9 and 25.0.0 - 36.0.10 and 37.0.0 - 44.0.2 and 45.0.0 - 45.0.1 GHSA-3p27-qvp9-27qf
Impacted packages
Timeline
Published
12 hours ago
October 02, 2026 at 12:00 PM UTC
Fixed (36.0.17)
7 hours ago
October 02, 2026 at 04:48 PM UTC
Fixed (49.0.2)
7 hours ago
October 02, 2026 at 04:48 PM UTC
Fixed (48.0.4)
6 hours ago
October 02, 2026 at 05:55 PM UTC
Last Modified
3 hours ago
October 02, 2026 at 08:30 PM UTC