Vulnerability RUSTSEC-2026-0324
Medium Risk
MEDIUM RISK
CVSS Score: 6.2
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
12 hours ago
October 02, 2026 at 12:00 PM UTC
Guest can panic host through filesystem timestamp before the epoch on wasip3
46.0.0 - 48.0.3
46.0.0 - 48.0.3
Summary
Guest can panic host through filesystem timestamp before the epoch on wasip3
Details
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-mr2v-56j5-cmfc For more information see the GitHub-hosted security advisory.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
12 hours ago
WASI preview 0 implementation of `poll_oneoff` circumvents fuel consumption
0.2.0 - 36.0.16 RUSTSEC-2026-0321
0.2.0 - 36.0.16 RUSTSEC-2026-0321
Unknown
12 hours ago
Excessive allocated memory on the host when guests don't have stdio
0.2.0 - 36.0.16 RUSTSEC-2026-0322
0.2.0 - 36.0.16 RUSTSEC-2026-0322
Unknown
12 hours ago
fd_readdir copies uninitialized struct padding into guest memory
0.2.0 - 36.0.16 RUSTSEC-2026-0323
0.2.0 - 36.0.16 RUSTSEC-2026-0323
Medium Risk
8 days ago
Guest can panic host through filesystem datetime overflow
0.2.0 - 36.0.15 RUSTSEC-2026-0314
0.2.0 - 36.0.15 RUSTSEC-2026-0314
Medium Risk
1 month ago
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
0.2.0 - 24.0.9 and 25.0.0 - 36.0.10 and 37.0.0 - 44.0.2 and 45.0.0 - 45.0.1 GHSA-3p27-qvp9-27qf
0.2.0 - 24.0.9 and 25.0.0 - 36.0.10 and 37.0.0 - 44.0.2 and 45.0.0 - 45.0.1 GHSA-3p27-qvp9-27qf
Impacted packages
Timeline
Published
12 hours ago
October 02, 2026 at 12:00 PM UTC
Fixed (49.0.2)
7 hours ago
October 02, 2026 at 04:48 PM UTC
Fixed (48.0.4)
6 hours ago
October 02, 2026 at 05:55 PM UTC
Last Modified
3 hours ago
October 02, 2026 at 08:30 PM UTC