wasmtime is vulnerable to Denial of Service (DoS)
69
Medium Risk
The WASIp3 implementation copies guest-provided bytes during file and HTTP stream write operations without capping the amount buffered on the host. A guest can request very large stream writes and force the host to allocate memory sized by guest-controlled input. Before the fix this allowed unbounded host memory growth and denial of service through resource exhaustion. The fix caps the number of bytes copied per chunk so host buffering no longer scales with untrusted guest input.
You are affected if you are using a version that falls within the vulnerable range and your embedding exposes the WASIp3 file or HTTP stream interfaces to guest-controlled writes.
wasmtime is vulnerable to Denial of Service (DoS) in versions 46.0.0 - 46.0.2 and 47.0.0 - 47.0.3.
Upgrade the wasmtime library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant