CVE Explorer
CVE-2026-35195
Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings between components contains a bug where the return value of a guest component's realloc is not validated before the host attempts to write through the pointer. This enables a guest to cause the host to write arbitrary transcoded string bytes to an arbitrary location up to 4GiB away from the base of linear memory. These writes on the host could hit unmapped memory o
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"wasmtime","vendor":"bytecodealliance","versions":[{"status":"affected","version":"< 24.0.7"},{"status":"affected","version":">= 25.0.0, < 36.0.7"},{"status":"affected","version":">= 37.0.0, < 42.0.2"},{"status":"affected","version":">= 43.0.0, < 44.0.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:fb737f4df77d7d7566c09677e3363f1c91d199879840c745dd4f75435cf6363f · sha256:db85e3861b14e98c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.1,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:fb737f4df77d7d7566c09677e3363f1c91d199879840c745dd4f75435cf6363f · sha256:db85e3861b14e98c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-787","description":"CWE-787: Out-of-bounds Write","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fb737f4df77d7d7566c09677e3363f1c91d199879840c745dd4f75435cf6363f · sha256:db85e3861b14e98c… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-394w-hwhg-8vgm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-394w-hwhg-8vgm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fb737f4df77d7d7566c09677e3363f1c91d199879840c745dd4f75435cf6363f · sha256:db85e3861b14e98c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.