RustSec logo

History ⋅ Edit ⋅ JSON (OSV)

RUSTSEC-2026-0321

WASI preview 0 implementation of poll_oneoff circumvents fuel consumption

Reported
Issued
Package
wasmtime-wasi (crates.io)
Type
Vulnerability
Aliases
References
CVSS Score
4 MEDIUM
CVSS Details
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality Impact
None
Integrity Impact
None
Availability Impact
Low
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Patched
  • >=36.0.17, <37.0.0
  • >=48.0.4, <49.0.0
  • >=49.0.2

Description

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-j366-h8gg-77pm For more information see the GitHub-hosted security advisory.

Advisory available under CC0-1.0 license.