Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    RUSTSEC-2026-0324 (GHSA-MR2V-56J5-CMFC)

    Vulnerability from osv_rustsec – Published: 2026-10-02 12:00 – Updated: 2026-10-02 20:27 – Source website
    VLAI
    Summary
    Guest can panic host through filesystem timestamp before the epoch on wasip3
    Details

    This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-mr2v-56j5-cmfc For more information see the GitHub-hosted security advisory.


    {
      "affected": [
        {
          "database_specific": {
            "categories": [],
            "cvss": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "informational": null
          },
          "ecosystem_specific": {
            "affected_functions": null,
            "affects": {
              "arch": [],
              "functions": [],
              "os": []
            }
          },
          "package": {
            "ecosystem": "crates.io",
            "name": "wasmtime-wasi",
            "purl": "pkg:cargo/wasmtime-wasi"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "46.0.0"
                },
                {
                  "fixed": "48.0.4"
                },
                {
                  "introduced": "49.0.0"
                },
                {
                  "fixed": "49.0.2"
                }
              ],
              "type": "SEMVER"
            }
          ],
          "versions": []
        }
      ],
      "aliases": [
        "GHSA-mr2v-56j5-cmfc"
      ],
      "database_specific": {
        "license": "CC0-1.0"
      },
      "details": "This is an entry in the RustSec database for the Wasmtime security advisory\nlocated at\nhttps://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-mr2v-56j5-cmfc\nFor more information see the GitHub-hosted security advisory.",
      "id": "RUSTSEC-2026-0324",
      "modified": "2026-10-02T20:27:46Z",
      "published": "2026-10-02T12:00:00Z",
      "references": [
        {
          "type": "PACKAGE",
          "url": "https://crates.io/crates/wasmtime-wasi"
        },
        {
          "type": "ADVISORY",
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0324.html"
        },
        {
          "type": "WEB",
          "url": "https://github.com/bytecodealliance/wasmtime/pull/14486"
        }
      ],
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Guest can panic host through filesystem timestamp before the epoch on wasip3"
    }