Fiche vulnérabilité
CVE-2026-27572 : faille élevée bytecodealliance wasmtime (CVSS 7.5)
Description
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/types.fields` resource is susceptible to panics when too many fields are added to the set of headers. Wasmtime's implementation in the `wasmtime-wasi-http` crate is backed by a data structure which panics when it reaches excessive capacity and this condition was not handled gracefully in Wasmtime. Panicking in a WASI implementation is a Denial of Service vector for embedders and is treated as a security vulnerability in Wasmtime. Wasmtime 24.0.6, 36.0.6, 40.0.4, 41.0.4, and 42.0.0 patch this vulnerability and return a trap to the guest instead of panicking. There are no known workarounds at this time. Embedders are encouraged to update to a patched version of Wasmtime.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 24 févr. 2026
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- bytecodealliance wasmtime
Références
- Fiche CVE-2026-27572 sur le NVD (NIST)
- docs.rs/http/1.4.0/http/header/
- github.com/bytecodealliance/wasmtime/commit/301dc7162cca5…
- github.com/bytecodealliance/wasmtime/releases/tag/v24.0.6
- github.com/bytecodealliance/wasmtime/releases/tag/v36.0.6
- github.com/bytecodealliance/wasmtime/releases/tag/v40.0.4
- github.com/bytecodealliance/wasmtime/releases/tag/v41.0.4
- github.com/bytecodealliance/wasmtime/security/advisories/…