Search CVE reports


Toggle filters

41 – 50 of 33695 results

Status is adjusted based on your filters.


CVE-2026-35195

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings between components contains a bug where the return value of a guest component's realloc is...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-35186

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backend contains a bug where translating the table.grow operator causes the result to be incorrectly typed. For...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34988

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 28.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of its pooling allocator contains a bug where in certain configurations the contents of linear memory can be leaked...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34987

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler backend may allow properly constructed guest Wasm to access host memory outside of...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34983

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free bugs. This bug is not controllable by guest Wasm programs. It can only be triggered by a specific sequence of...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34971

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilation backend contains a bug on aarch64 when performing a certain shape of heap accesses which means that the...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34946

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a vulnerability where the compilation of the table.fill instruction can result in a host panic. This means...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34945

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a bug where a 64-bit table, part of the memory64 proposal of WebAssembly, incorrectly translated the...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34944

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabled Wasmtime's compilation of the f64x2.splat WebAssembly instruction with Cranelift may load 8 more bytes than...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages

CVE-2026-34943

Medium priority
Needs evaluation

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a possible panic which can happen when a flags-typed component model value is lifted with the Val type. If bits are set outside...

1 affected package

rust-wasmtime

Package 24.04 LTS
rust-wasmtime Needs evaluation
Show less packages