CVE Explorer
CVE-2026-54786
Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; versions 37.0.0 through those before 44.0.3; and versions 45.0.0 and 45.0.1 contain a native implementation of WASIp1 which suffers from a leak in the fd_renumber function where the file descriptor being renumbered to is not properly closed. Wasmtime's implementation erroneously only updated the table of descriptors for WASIp1 and didn't update the underlying table of descriptors
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-772","description":"CWE-772: Missing Release of Resource after Effective Lifetime","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:07a5ad28386ee9bfd7474eabfdc50c9d3da5f58c3038b8a35e029195a60dff83 · sha256:ebc194e7b82c0919… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:07a5ad28386ee9bfd7474eabfdc50c9d3da5f58c3038b8a35e029195a60dff83 · sha256:ebc194e7b82c0919… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"wasmtime","vendor":"bytecodealliance","versions":[{"status":"affected","version":"< 24.0.10"},{"status":"affected","version":">= 25.0.0, < 36.0.11"},{"status":"affected","version":">= 37.0.0, < 44.0.3"},{"status":"affected","version":">= 45.0.0, < 45.0.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:07a5ad28386ee9bfd7474eabfdc50c9d3da5f58c3038b8a35e029195a60dff83 · sha256:ebc194e7b82c0919… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":2.3,"baseSeverity":"LOW","privilegesRequired":"LOW","subAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:07a5ad28386ee9bfd7474eabfdc50c9d3da5f58c3038b8a35e029195a60dff83 · sha256:ebc194e7b82c0919… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-772","description":"CWE-772: Missing Release of Resource after Effective Lifetime","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:07a5ad28386ee9bfd7474eabfdc50c9d3da5f58c3038b8a35e029195a60dff83 · sha256:ebc194e7b82c0919… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:07a5ad28386ee9bfd7474eabfdc50c9d3da5f58c3038b8a35e029195a60dff83 · sha256:ebc194e7b82c0919… · /containers/cna/problemTypes/1/descriptions/0
Source references
1 source assertion{"name":"https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-3p27-qvp9-27qf","tags":["x_refsource_CONFIRM"],"url":"https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-3p27-qvp9-27qf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:07a5ad28386ee9bfd7474eabfdc50c9d3da5f58c3038b8a35e029195a60dff83 · sha256:ebc194e7b82c0919… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.