PT-2026-31692 · Bytecode Alliance · Wasmtime

CVE-2026-35186

·

Published

2026-04-09

·

Updated

2026-08-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wasmtime versions 25.0.0 through 36.0.6, 42.0.2, and 43.0.1
Description Wasmtime, a runtime for WebAssembly, has an issue in its Winch compiler backend where the translation of the table.grow operator results in an incorrect type. Specifically, for 32-bit tables, the result is tagged as a 64-bit value instead of a 32-bit value within Winch. This can lead to a denial of service (DoS) by crashing the host process, a correctness issue within Winch, and a potential leak of up to 16 bytes before linear memory. The vulnerability is exploitable when guard pages before linear memory are disabled. The default compiler for Wasmtime is Cranelift, and the default configuration includes guard pages, meaning the default configuration is not affected.
Recommendations Update to Wasmtime version 36.0.7, 42.0.2, or 43.0.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35186
GHSA-F984-PCP8-V2P7
JLSEC-2026-1363
OPENSUSE-SU-2026:10715-1
OPENSUSE-SU-2026:20749-1
RUSTSEC-2026-0094
SUSE-SU-2026:21789-1

Affected Products

Wasmtime