This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate wasmtime-wasi

Dependencies

(28 total, 16 outdated, 1 insecure)

CrateRequiredLatestStatus
 anyhow^1.0.221.0.104up to date
 async-trait^0.1.710.1.92up to date
 bitflags^2.02.13.2up to date
 bytes^1.41.12.1up to date
 cap-fs-ext^2.0.04.0.3out of date
 cap-net-ext^2.0.04.0.3out of date
 cap-rand^2.0.04.0.3out of date
 cap-std^2.0.04.0.3out of date
 cap-time-ext^2.0.04.0.3out of date
 fs-set-times^0.20.00.20.3up to date
 futures^0.3.270.3.34up to date
 io-extras^0.18.00.19.0out of date
 io-lifetimes^2.0.23.0.1out of date
 libc^0.2.600.2.189up to date
 log^0.4.80.4.34up to date
 once_cell^1.12.01.21.4up to date
 rustix^0.38.211.1.5out of date
 system-interface^0.26.00.27.3out of date
 thiserror^1.0.432.0.20out of date
 tokio^1.26.01.53.1up to date
 tracing^0.1.260.1.44up to date
 url^2.3.12.5.8up to date
 wasi-cap-std-sync=17.0.117.0.3out of date
 wasi-common=17.0.146.0.3out of date
 wasi-tokio=17.0.117.0.3out of date
 wasmtime ⚠️^17.0.148.0.2insecure
 wiggle=17.0.148.0.2out of date
 windows-sys^0.52.00.61.2out of date

Dev dependencies

(6 total, 1 outdated, 1 insecure)

CrateRequiredLatestStatus
 libc^0.2.600.2.189up to date
 tempfile^3.1.03.27.0up to date
 test-log^0.20.2.21up to date
 tokio^1.26.01.53.1up to date
 tracing-subscriber^0.3.10.3.23up to date
 wasmtime ⚠️^17.0.148.0.2insecure

Security Vulnerabilities

wasmtime: Wasmtime doesn't fully sandbox all the Windows device filenames

RUSTSEC-2024-0438

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-c2f5-jxjv-2hh8. For more information see the GitHub-hosted security advisory.

wasmtime: Host panic with `fd_renumber` WASIp1 function

RUSTSEC-2025-0046

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-fm79-3f68-h2fc. For more information see the GitHub-hosted security advisory.

wasmtime: Unsound API access to a WebAssembly shared linear memory

RUSTSEC-2025-0118

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-hc7m-r6v8-hg9q For more information see the GitHub-hosted security advisory.

wasmtime: Guest-controlled resource exhaustion in WASI implementations

RUSTSEC-2026-0020

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-852m-cvvp-9p4w For more information see the GitHub-hosted security advisory.

wasmtime: Panic adding excessive fields to a `wasi:http/types.fields` instance

RUSTSEC-2026-0021

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-243v-98vx-264h For more information see the GitHub-hosted security advisory.

wasmtime: Panic when lifting `flags` component value

RUSTSEC-2026-0085

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-m758-wjhj-p3jq For more information see the GitHub-hosted security advisory.

wasmtime: Host data leakage with 64-bit tables and Winch

RUSTSEC-2026-0086

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-m9w2-8782-2946 For more information see the GitHub-hosted security advisory.

wasmtime: Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on Cranelift x86-64

RUSTSEC-2026-0087

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-qqfj-4vcm-26hv For more information see the GitHub-hosted security advisory.

wasmtime: Data leakage between pooling allocator instances

RUSTSEC-2026-0088

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-6wgr-89rj-399p For more information see the GitHub-hosted security advisory.

wasmtime: Host panic when Winch compiler executes `table.fill`

RUSTSEC-2026-0089

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-q49f-xg75-m9xw For more information see the GitHub-hosted security advisory.

wasmtime: Out-of-bounds write or crash when transcoding component model strings

RUSTSEC-2026-0091

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-394w-hwhg-8vgm For more information see the GitHub-hosted security advisory.

wasmtime: Panic when transcoding misaligned component model UTF-16 strings

RUSTSEC-2026-0092

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-jxhv-7h78-9775 For more information see the GitHub-hosted security advisory.

wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding

RUSTSEC-2026-0093

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-hx6p-xpx3-jvvv For more information see the GitHub-hosted security advisory.

wasmtime: Improperly masked return value from `table.grow` with Winch compiler backend

RUSTSEC-2026-0094

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-f984-pcp8-v2p7 For more information see the GitHub-hosted security advisory.

wasmtime: Wasmtime with Winch compiler backend may allow a sandbox-escaping memory access

RUSTSEC-2026-0095

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-xx5w-cvp6-jv83 For more information see the GitHub-hosted security advisory.

wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift

RUSTSEC-2026-0096

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-jhxm-h53p-jm7w For more information see the GitHub-hosted security advisory.

wasmtime: Stores can mix up type indices between engines

RUSTSEC-2026-0222

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-hgjw-h833-99q9 For more information see the GitHub-hosted security advisory.

wasmtime: Filesystem sandbox escape when paths or symlinks contain trailing slashes

RUSTSEC-2026-0269

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-vqjp-4c8c-hfgg For more information see the GitHub-hosted security advisory.