CVE-2026-34941Disclosure(bytecodealliance / wasmtime)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch bytecodealliance wasmtime systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability where when transcoding a UTF-16 string to the latin1+utf16 component-model encoding it would incorrectly validate the byte length of the input string when performing a bounds check. Specifically the number of code units were checked instead of the byte length, which is twice the size of the code units. This vulnerability can cause the host to read beyond the end of a WebAssembly's linear memory in an attempt to transcode nonexistent bytes. In Wasmtime's default configuration this will read unmapped memory on a guard page, terminating the process with a segfault. Wasmtime can be configured, however, without guard pages which would mean that host memory beyond the end of linear memory may be read and interpreted as UTF-16. A host segfault is a denial-of-service vulnerability in Wasmtime, and possibly being able to read beyond the end of linear memory is additionally a vulnerability. Note that reading beyond the end of linear memory requires nonstandard configuration of Wasmtime, specifically with guard pages disabled. This vulnerability is fixed in 24.0.7, 36.0.7, 42.0.2, and 43.0.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wasmtime

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
wasmtime

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-09: 2Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 204-09
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34941 Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability where when transcoding a UTF-16 string to the la… https://www.cve.org/CVERecord?id=CVE-2026-34941 ----- Traducción: CVE-2026-34941 Was… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑34941 affecting Wasmtime before certain releases, links to the CVE record, and provides a brief technical description of the vulnerability, but no PoC, exploit, or patch details.

    0000033
    67 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-34941 Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability where when transcoding a UTF-16 string to the la… https://www.cve.org/CVERecord?id=CVE-2026-34941

    Post summary

    The advisory confirms a vulnerability in Wasmtime related to UTF‑16 string transcoding, lists pre‑patched releases, and implies a fix is available, but no proof of exploitation or PoC is provided.

    00000151
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbytecodealliancewasmtime-rust-

Explore more