PatchSiren cyber security CVE debrief
CVE-2026-44216 bytecodealliance CVE debrief
A denial-of-service vulnerability exists in Wasmtime's WebAssembly table allocation logic. From versions 30.0.0 through 36.0.8, 37.0.0 through 43.0.2, and 44.0.0, checked arithmetic operations panic on overflow when allocating tables with extremely large sizes. This condition is triggerable via the WebAssembly memory64 proposal, which extends table sizes to the 64-bit range. The panic occurs during module or component instantiation when attempting to create oversized tables. The vulnerability has been patched in versions 36.0.8, 43.0.2, and 44.0.1. No known exploitation in the wild has been reported.
- Vendor
- bytecodealliance
- Product
- wasmtime
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-07-28
Who should care
Organizations running Wasmtime as a WebAssembly runtime for untrusted or third-party modules, particularly those supporting the memory64 proposal. Cloud platforms offering WebAssembly execution services and developers embedding Wasmtime in serverless or edge computing environments should prioritize patching.
Technical summary
The vulnerability stems from checked arithmetic overflow in table allocation code paths. When the WebAssembly memory64 proposal is enabled, table sizes can exceed 32-bit limits, causing multiplication operations during allocation to overflow. The Rust panic handler terminates the runtime, resulting in denial of service. The fix implements proper overflow handling or bounds checking before arithmetic operations.
Defensive priority
medium
Recommended defensive actions
- Upgrade Wasmtime to patched versions 36.0.8, 43.0.2, or 44.0.1 depending on your current release branch
- Review WebAssembly module sources for untrusted memory64 table declarations
- Implement resource limits on WebAssembly instantiation to prevent excessive table allocation attempts
- Monitor application logs for panic conditions during module instantiation
Evidence notes
The vulnerability was disclosed via GitHub Security Advisory GHSA-p8xm-42r7-89xg and subsequently published to NVD. The issue affects multiple version ranges due to branching release patterns. CVSS 4.0 vector indicates network attack vector with low attack complexity, privileged access requirements, and high availability impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44216 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44216
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44216 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44216
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-p8xm-42r7-89xg
[email protected] - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.