CVE-2026-34987Disclosure(bytecodealliance / wasmtime)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler backend may allow properly constructed guest Wasm to access host memory outside of its linear-memory sandbox. This vulnerability requires use of the Winch compiler (-Ccompiler=winch). By default, Wasmtime uses its Cranelift backend, not Winch. With Winch, the same incorrect assumption is present in theory on both aarch64 and x86-64. The aarch64 case has an observed-working proof of concept, while the x86-64 case is theoretical and may not be reachable in practice. This Winch compiler bug can allow the Wasm guest to access memory before or after the linear-memory region, independently of whether pre- or post-guard regions are configured. The accessible range in the initial bug proof-of-concept is up to 32KiB before the start of memory, or ~4GiB after the start of memory, independently of the size of pre- or post-guard regions or the use of explicit or guard-region-based bounds checking. However, the underlying bug assumes a 32-bit memory offset stored in a 64-bit register has its upper bits cleared when it may not, and so closely related variants of the initial proof-of-concept may be able to access truly arbitrary memory in-process. This could result in a host process segmentation fault (DoS), an arbitrary data leak from the host process, or with a write, potentially an arbitrary RCE. This vulnerability is fixed in 36.0.7, 42.0.2, and 43.0.1.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wasmtime

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-09); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
wasmtime

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-10: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 104-0904-1004-11
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure1General1
2026-04-101
Disclosure1
2026-04-111
Disclosure1
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Wasmtime` on `aarch64` with `Winch` backend is vulnerable to a sandbox-escaping memory access (CVE-2026-34987). Review `Wasmtime` deployments, especially on ARM-based systems. #Wasmtime #WebAssembly #Security https://www.pulsepatch.io/posts/cve-2026-34987-wasmtime-sandbox-escape-aarch64

    Post summary

    A new vulnerability (CVE-2026-34987) affecting Wasmtime on aarch64 with the Winch backend has been disclosed as a sandbox-escaping memory access, but no patches, exploits, or PoC details are provided. Users are advised to review their Wasmtime deployments, especially on ARM-based systems.

    0000046
    11 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34987: Wasmtime with Winch compiler bac... Winch compiler's 32-bit offset assumption on aarch64 opens 4GB+ memory window - sandbox is toilet paper when upper bits... https://zerodaysignal.com/vulnerability/CVE-2026-34987 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑34987, describing a 32‑bit offset flaw in Winch compiler on aarch64 that creates a large memory window, and supplies a link to a source likely containing deeper details.

    0000064
    204 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-34987 Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler backend may allow pro… https://www.cve.org/CVERecord?id=CVE-2026-34987 ----- Traducción: CVE-2026-34987 Was… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑34987 affecting specific Wasmtime releases, lists technical details of the vulnerability, but lacks any PoC, exploit code, or evidence of active attacks or fixes.

    0000031
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34987 Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler backend may allow pro… https://www.cve.org/CVERecord?id=CVE-2026-34987

    Post summary

    An initial disclosure of CVE-2026-34987 details potential vulnerabilities in Wasmtime’s Winch compiler across specified versions; no PoC, exploit, or patch information is included.

    00000122
    57.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appbytecodealliancewasmtime-rust-
Appbytecodealliancewasmtime43.0.0rust-

Explore more