Vulnerability in Wasmtime Affecting WebAssembly Runtime
CVE-2026-104855

2LOW

Key Information:

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104855?

A flaw in the Wasmtime WebAssembly runtime can lead to exposure of invalid intermediate states during bulk operations such as memory.copy, table.grow, and array.copy. This issue arises when an embedder mutates a Store in a callback or continues using a Store post-cancellation or trap. It may result in null elements from cancelled table growths, invalid raw pointers from memory.copy, and corrupted GC pointers during array.copy. Though embeddings that only access host data and discard a Store after certain timeouts are unaffected, the vulnerability poses risks of crashes and memory issues in other scenarios. The problem was addressed in Wasmtime versions 46.0.2 and 47.0.3.

Affected Version(s)

wasmtime >= 46.0.0, < 46.0.2 < 46.0.0, 46.0.2

wasmtime >= 47.0.0, < 47.0.3 < 47.0.0, 47.0.3

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.