Vulnerability in Wasmtime Affecting WebAssembly Runtime
CVE-2026-104855
What is CVE-2026-104855?
A flaw in the Wasmtime WebAssembly runtime can lead to exposure of invalid intermediate states during bulk operations such as memory.copy, table.grow, and array.copy. This issue arises when an embedder mutates a Store in a callback or continues using a Store post-cancellation or trap. It may result in null elements from cancelled table growths, invalid raw pointers from memory.copy, and corrupted GC pointers during array.copy. Though embeddings that only access host data and discard a Store after certain timeouts are unaffected, the vulnerability poses risks of crashes and memory issues in other scenarios. The problem was addressed in Wasmtime versions 46.0.2 and 47.0.3.
Affected Version(s)
wasmtime >= 46.0.0, < 46.0.2 < 46.0.0, 46.0.2
wasmtime >= 47.0.0, < 47.0.3 < 47.0.0, 47.0.3
