wasmtime is vulnerable to Uncontrolled Resource Consumption
10
Low Risk
Wasmtime's dynamically typed Val API lifts guest returned records, tuples, variants, enums, and flags without charging the hostcall fuel limit for the host memory each one allocates. A guest can shape a returned value so the host allocates roughly 100x more memory than fuel accounting records, leading to host memory exhaustion through a gap left by the earlier mitigation for GHSA-852m-cvvp-9p4w. Hosts that only use the static APIs generated by bindgen! are unaffected. The fix charges fuel for each field, tuple element, and variant, enum, or flags entry as Val::lift recurses.
You are affected if you are using a version that falls within the vulnerable range and your host embeds Wasmtime using the dynamically typed Val API to read values returned from a guest.
wasmtime is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 36.0.15, 0.0.1 - 48.0.2 and 49.0.0 - 49.0.0.
Upgrade the wasmtime library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.