Denial-of-Service Vulnerability in Wasmtime Runtime by Bytecode Alliance
CVE-2026-34946

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 April 2026

What is CVE-2026-34946?

A vulnerability exists in the Winch compiler of the Wasmtime runtime, which can lead to a denial-of-service condition. A compromised or malicious WebAssembly guest can trigger a host panic through improperly referenced tables in the table.fill instruction. This misconfiguration arises from a historical code refactor that failed to update key indexing methods. The flaw affects versions from 25.0.0 to just before 36.0.7, as well as versions 42.0.2 and 43.0.1. To ensure system stability and security, users should upgrade to the patched versions.

Affected Version(s)

wasmtime >= 25.0.0, < 36.0.7 < 25.0.0, 36.0.7

wasmtime >= 37.0.0, < 42.0.2 < 37.0.0, 42.0.2

wasmtime >= 43.0.0, < 44.0.1 < 43.0.0, 44.0.1

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.