Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend Moderate
CVE-2026-35186 was published for wasmtime (Rust) Apr 10, 2026
shumbo Credited to shumbo, bholley, and deian bholley bholley
deian deian
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access Critical
CVE-2026-34987 was published for wasmtime (Rust) Apr 10, 2026
shumbo Credited to shumbo, bholley, and deian bholley bholley
deian deian
Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift Critical
CVE-2026-34971 was published for wasmtime (Rust) Apr 9, 2026
shumbo Credited to shumbo, bholley, and deian bholley bholley
deian deian
Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding Moderate
CVE-2026-34941 was published for wasmtime (Rust) Apr 9, 2026
shumbo Credited to shumbo and deian deian deian
ProTip! Advisories are also available from the GraphQL API