Junglewise Threat Intelligence

CVE-2026-34988: Bytecode Alliance Wasmtime data leakage in pooling allocator

CVE-2026-34988 · Severity: medium · CVSS 4 · Published 2026-04-09

Technologies: wasmtime (crates.io). Vendors: crates.io.

Executive brief

Wasmtime is a runtime for executing WebAssembly code in a secure, isolated environment. A bug in its memory management system can allow one guest program to access the private memory of a previously running program under specific configurations. This could lead to sensitive data leakage between different users or applications sharing the same infrastructure.

Technical details

A logic error in Wasmtime's pooling allocator causes a divergence between runtime memory resetting and compile-time assumptions. Specifically, the allocator may use an incorrect predicate to determine if virtual memory permissions need to be reset when a linear memory slot is reused. If the pooling allocator is active, memory guard size is 0, and memory reservation is less than 4GiB (matching max_memory_size), the system fails to trigger a segfault on out-of-bounds loads. This allows a subsequent WebAssembly instance to read the memory remains of a previous instance. The issue is fixed in versions 36.0.7, 42.0.2, and 43.0.1.

Affected products

  • Bytecode Alliance Wasmtime >= 28.0.0, < 36.0.7; >= 37.0.0, < 42.0.2; 43.0.0

Timeline

  • 2026-04-09: disclosed
  • 2026-04-09: advisory
  • 2026-04-09: patched

References

Related threats