CVE-2024-30266: Bytecodealliance Wasmtime
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this panic. This vulnerability has been patched in version 19.0.1.
Affected products
- Bytecodealliance Wasmtime: version 19.0.0 only
Published 2024-04-04. Last modified 2026-06-17.