Junglewise Threat Intelligence

CVE-2026-35195: Bytecode Alliance Wasmtime out-of-bounds write in string transcoding

CVE-2026-35195 · Severity: medium · CVSS 4 · Published 2026-04-09

Technologies: wasmtime (crates.io). Vendors: crates.io.

Executive brief

Wasmtime is a runtime for executing WebAssembly code, often used to run untrusted code in a secure sandbox. A flaw in how it handles text conversion between different components allows a malicious guest program to write data to memory locations it should not be able to access. In most cases, this will cause the application to crash, but in specific configurations, it could lead to the corruption of sensitive data or other programs running on the same system.

Technical details

A vulnerability exists in Wasmtime's implementation of string transcoding between components. The root cause is a failure to validate the return value of a guest component's 'realloc' function before the host attempts to write transcoded bytes through the resulting pointer. An attacker controlling a guest component can trigger an out-of-bounds write of arbitrary transcoded string bytes to locations up to 4GiB away from the base of linear memory. While default configurations (4GiB virtual memory reservation) typically result in a process abort due to an unhandled fault (DoS), configurations with smaller reservations or no guard pages may allow corruption of host data structures or other guest memories. Patches are available in versions 24.0.7, 36.0.7, 42.0.2, and 43.0.1.

Affected products

  • Bytecode Alliance wasmtime < 24.0.7, >= 25.0.0 < 36.0.7, >= 37.0.0 < 42.0.2, 43.0.0

Timeline

  • 2026-04-09: disclosed
  • 2026-04-09: patched
  • 2026-04-09: advisory

References

Related threats