CVE-2026-34942Disclosure(bytecodealliance / wasmtime)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings into the Component Model's utf16 or latin1+utf16 encodings improperly verified the alignment of reallocated strings. This meant that unaligned pointers could be passed to the host for transcoding which would trigger a host panic. This panic is possible to trigger from malicious guests which transfer very specific strings across components with specific addresses. Host panics are considered a DoS vector in Wasmtime as the panic conditions are controlled by the guest in this situation. This vulnerability is fixed in 24.0.7, 36.0.7, 42.0.2, and 43.0.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wasmtime

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
wasmtime

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-07-02: 1Technical Details · 2026-04-09: 204-0907-02
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-07-021
General1
Full discourse3 posts
  • durp@durpxmr
    General

    @usr_bin_roygbiv @zekramu Ok i stand corrected its shitty code built on rust. CVE-2026-55407 CVE-2026-35195 CVE-2026-34942 RUSTSEC-2026-0185

    Post summary

    The message merely references several CVEs and comments on Rust code quality, without providing evidence of PoC, exploit tools, active exploitation, patches, or technical details.

    0001086
    441 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34942 Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings into the Component Model's utf16 … https://www.cve.org/CVERecord?id=CVE-2026-34942 ----- Traducción: CVE-2026-34942 Was… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-34942, noting affected Wasmtime versions and describing a UTF‑16 transcoding issue, but provides no PoC, exploit, or mitigation details.

    0000038
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34942 Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings into the Component Model's utf16 … https://www.cve.org/CVERecord?id=CVE-2026-34942

    Post summary

    A CVE has been disclosed for Wasmtime, indicating that versions up to 24.0.7, 36.0.7, 42.0.2, and 43.0.1 contain a string transcoding defect in the Component Model’s UTF‑16 implementation. No exploit or patch details are provided.

    00000140
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbytecodealliancewasmtime-rust-

Explore more