Vulnerability RUSTSEC-2026-0326
Medium Risk
MEDIUM RISK
CVSS Score: 5.7
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
12 hours ago
October 02, 2026 at 12:00 PM UTC
Rooting for GC values live across `try_call` may be missing, causing GC heap corruption
47.0.0 - 48.0.3
47.0.0 - 48.0.3
Summary
Rooting for GC values live across `try_call` may be missing, causing GC heap corruption
Details
This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-hw8m-q44c-ggrf For more information see the GitHub-hosted security advisory.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
1 hour ago
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state
46.0.0 - 46.0.1 and 47.0.0 - 47.0.2 GHSA-2hw9-mc66-jc2q
46.0.0 - 46.0.1 and 47.0.0 - 47.0.2 GHSA-2hw9-mc66-jc2q
Unknown
12 hours ago
Mis-typed WebAssembly tag imports can lead to GC heap corruption
47.0.0 - 48.0.3 RUSTSEC-2026-0325
47.0.0 - 48.0.3 RUSTSEC-2026-0325
Unknown
12 hours ago
Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow
39.0.0 - 48.0.3 RUSTSEC-2026-0327
39.0.0 - 48.0.3 RUSTSEC-2026-0327
Medium Risk
8 days ago
`call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification
47.0.0 - 48.0.2 RUSTSEC-2026-0315
47.0.0 - 48.0.2 RUSTSEC-2026-0315
Unknown
8 days ago
Dynamic record lifting can allocate beyond the hostcall fuel limit
0.0.0 - 36.0.15 RUSTSEC-2026-0316
0.0.0 - 36.0.15 RUSTSEC-2026-0316
Impacted packages
Timeline
Published
12 hours ago
October 02, 2026 at 12:00 PM UTC
Fixed (49.0.2)
7 hours ago
October 02, 2026 at 04:48 PM UTC
Fixed (48.0.4)
6 hours ago
October 02, 2026 at 05:55 PM UTC
Last Modified
3 hours ago
October 02, 2026 at 08:30 PM UTC