CVEs we hold for Bytecodealliance
Records whose assigning authority named Bytecodealliance as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-58494Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destinationbytecodealliance wasmtime
CVE-2026-47261Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restrictionbytecodealliance wasmtime
CVE-2026-44216Wasmtime: Panic when allocating a table exceeding the size of the host's address spacebytecodealliance wasmtime
CVE-2026-35195Wasmtime has an out-of-bounds write or crash when transcoding component model stringsbytecodealliance wasmtime
CVE-2026-35186Wasmtime has an improperly masked return value from `table.grow` with Winch compiler backendbytecodealliance wasmtime
CVE-2026-34987Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory accessbytecodealliance wasmtime
CVE-2026-34983Wasmtime has a use-after-free bug after cloning `wasmtime::Linker`bytecodealliance wasmtime
CVE-2026-34971Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Craneliftbytecodealliance wasmtime
CVE-2026-34946Wasmtime's host panics when Winch compiler executes `table.fill`bytecodealliance wasmtime
CVE-2026-34944Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64bytecodealliance wasmtime
CVE-2026-34941Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcodingbytecodealliance wasmtime
CVE-2026-27572Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instancebytecodealliance wasmtime
CVE-2026-27204Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustionbytecodealliance wasmtime
CVE-2026-27195Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` futurebytecodealliance wasmtime
CVE-2026-24116Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64bytecodealliance wasmtime
CVE-2025-64713WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling…bytecodealliance wasm-micro-runtime
CVE-2025-64704WebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instructionbytecodealliance wasm-micro-runtime
CVE-2025-64345Wasmtime provides unsound API access to a WebAssembly shared linear memorybytecodealliance wasmtime
CVE-2025-62711Wasmtime vulnerable to segfault when using component resourcesbytecodealliance wasmtime
CVE-2025-61670Wasmtime has memory leak in C API with `externref` and `anyref` typesbytecodealliance wasmtime
CVE-2025-58749WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT modebytecodealliance wasm-micro-runtime
CVE-2025-54126WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specifiedbytecodealliance wasm-micro-runtime
CVE-2025-43853iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi featurebytecodealliance wasm-micro-runtime
CVE-2024-51756cap-std doesn't fully sandbox all the Windows device filenamesbytecodealliance cap-std
CVE-2024-51745Wasmtime doesn't fully sandbox all the Windows device filenamesbytecodealliance wasmtime
CVE-2024-47813Wasmtime race condition could lead to WebAssembly control-flow integrity and type safety violationsbytecodealliance wasmtime
CVE-2024-47763Wasmtime runtime crash when combining tail calls with trapping importsbytecodealliance wasmtime
CVE-2024-43806`rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosionbytecodealliance rustix
CVE-2024-30266Wasmtime vulnerable to panic when using a dropped extenref-typed element segmentbytecodealliance wasmtime
CVE-2023-41880Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64bytecodealliance wasmtime
CVE-2023-26489Guest-controlled out-of-bounds read/write on x86_64 in wasmtimebytecodealliance wasmtime
CVE-2022-39394wasmtime_trap_code C API function has out of bounds write vulnerabilitybytecodealliance wasmtime
CVE-2022-39393Wasmtime vulnerable to data leakage between instances in the pooling allocatorbytecodealliance wasmtime
CVE-2022-39392Wasmtime vulnerable to out of bounds read/write with zero-memory-pages configurationbytecodealliance wasmtime
CVE-2022-31169Cranelift vulnerable to miscompilation of constant values in division on AArch64bytecodealliance wasmtime
CVE-2022-31104Miscompilation of `i8x16.swizzle` and `select` with v128 inputs in Wasmtimebytecodealliance wasmtime
CVE-2021-39219Wrong type for `Linker`-define functions when used across two `Engine`sbytecodealliance wasmtime
CVE-2021-39218Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtimebytecodealliance wasmtime
CVE-2021-32629Memory access due to code generation flaw in Cranelift modulebytecodealliance wasmtime
52 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.