Vulnerability RUSTSEC-2026-0325
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
12 hours ago
October 02, 2026 at 12:00 PM UTC
Mis-typed WebAssembly tag imports can lead to GC heap corruption
47.0.0 - 48.0.3
47.0.0 - 48.0.3
Summary
Mis-typed WebAssembly tag imports can lead to GC heap corruption
Details
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-cfhf-m2cr-62wj For more information see the GitHub-hosted security advisory.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
1 hour ago
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state
46.0.0 - 46.0.1 and 47.0.0 - 47.0.2 GHSA-2hw9-mc66-jc2q
46.0.0 - 46.0.1 and 47.0.0 - 47.0.2 GHSA-2hw9-mc66-jc2q
Medium Risk
12 hours ago
Rooting for GC values live across `try_call` may be missing, causing GC heap corruption
47.0.0 - 48.0.3 RUSTSEC-2026-0326
47.0.0 - 48.0.3 RUSTSEC-2026-0326
Unknown
12 hours ago
Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow
39.0.0 - 48.0.3 RUSTSEC-2026-0327
39.0.0 - 48.0.3 RUSTSEC-2026-0327
Medium Risk
8 days ago
`call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification
47.0.0 - 48.0.2 RUSTSEC-2026-0315
47.0.0 - 48.0.2 RUSTSEC-2026-0315
Unknown
8 days ago
Dynamic record lifting can allocate beyond the hostcall fuel limit
0.0.0 - 36.0.15 RUSTSEC-2026-0316
0.0.0 - 36.0.15 RUSTSEC-2026-0316
Impacted packages
Timeline
Published
12 hours ago
October 02, 2026 at 12:00 PM UTC
Fixed (49.0.2)
7 hours ago
October 02, 2026 at 04:48 PM UTC
Fixed (48.0.4)
6 hours ago
October 02, 2026 at 05:55 PM UTC
Last Modified
3 hours ago
October 02, 2026 at 08:30 PM UTC