Intel

AIKIDO-2026-581022

wasmtime is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource ConsumptionGHSA-jqpg-j7w6-42pr Published 2 days ago

10

Low Risk

This Affects:

RUSTwasmtime
0.0.1 - 36.0.15
Fixed in 36.0.16
0.0.1 - 48.0.2
Fixed in 48.0.3
49.0.0 - 49.0.0
Fixed in 49.0.1
Are you affected? Scan for Free

TL;DR

Wasmtime's dynamically typed Val API lifts guest returned records, tuples, variants, enums, and flags without charging the hostcall fuel limit for the host memory each one allocates. A guest can shape a returned value so the host allocates roughly 100x more memory than fuel accounting records, leading to host memory exhaustion through a gap left by the earlier mitigation for GHSA-852m-cvvp-9p4w. Hosts that only use the static APIs generated by bindgen! are unaffected. The fix charges fuel for each field, tuple element, and variant, enum, or flags entry as Val::lift recurses.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your host embeds Wasmtime using the dynamically typed Val API to read values returned from a guest.

Background info

wasmtime is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 36.0.15, 0.0.1 - 48.0.2 and 49.0.0 - 49.0.0.

How to fix this

Upgrade the wasmtime library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform