PT-2026-31684 · Bytecode Alliance · Wasmtime

CVE-2026-34943

·

Published

2026-04-09

·

Updated

2026-08-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wasmtime versions prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1
Description Wasmtime, a runtime for WebAssembly, may experience a panic when a flags-typed component model value is lifted with the Val type. This occurs if bits are set outside the expected flags, leading to a guest-controlled panic within the host, which is considered a denial-of-service vector. This issue specifically affects flags-typed values within a WIT interface and the lifting process into Val, not the flags! macro.
Recommendations Update to Wasmtime version 24.0.7, 36.0.7, 42.0.2, or 43.0.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34943
GHSA-M758-WJHJ-P3JQ
JLSEC-2026-1356
OPENSUSE-SU-2026:10715-1
OPENSUSE-SU-2026:20749-1
RUSTSEC-2026-0085
SUSE-SU-2026:21789-1

Affected Products

Wasmtime