Ad

CVE-2026-27572

MEDIUM CVSS 4.0: 6.9 EPSS 0.03%
Updated Feb 25, 2026
Bytecodealliance
Parameter Value
CVSS 6.9 (MEDIUM)
Affected Versions 25.0.0 — 41.0.4
Fixed In 24.0.6
Type CWE-770 (Allocation Without Limits)
Vendor Bytecodealliance
Public PoC No

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/types.fields` resource is susceptible to panics when too many fields are added to the set of headers. Wasmtime's implementation in the `wasmtime-wasi-http` crate is backed by a data structure which panics when it reaches excessive capacity and this condition was not handled gracefully in Wasmtime.

Panicking in a WASI implementation is a Denial of Service vector for embedders and is treated as a security vulnerability in Wasmtime. Wasmtime 24.0.6, 36.0.6, 40.0.4, 41.0.4, and 42.0.0 patch this vulnerability and return a trap to the guest instead of panicking. There are no known workarounds at this time.

Embedders are encouraged to update to a patched version of Wasmtime.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
Low
Basic privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 4

Configuration From (including) Up to (excluding)
Bytecodealliance Wasmtime
cpe:2.3:a:bytecodealliance:wasmtime:*:*:*:*:*:rust:*:*
24.0.6
Bytecodealliance Wasmtime
cpe:2.3:a:bytecodealliance:wasmtime:*:*:*:*:*:rust:*:*
25.0.0 36.0.6
Bytecodealliance Wasmtime
cpe:2.3:a:bytecodealliance:wasmtime:*:*:*:*:*:rust:*:*
37.0.0 40.0.4
Bytecodealliance Wasmtime
cpe:2.3:a:bytecodealliance:wasmtime:*:*:*:*:*:rust:*:*
41.0.0 41.0.4