{"id":"CVE-2026-44216","aliases":["GHSA-p8xm-42r7-89xg","RUSTSEC-2026-0114"],"url":"https://o3.security/vulnerability/CVE-2026-44216","summary":"Wasmtime: Panic when allocating a table exceeding the size of the host's address space","details":"Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked on overflow. This overflow is possible to trigger, and thus panic, when a table with an extremely large size is allocated. This is possible with the WebAssembly memory64 proposal where tables can have sizes in the 64-bit range as opposed to the previous 32-bit range which would not overflow. The panic happens when attempting to create a very large table, such as when instantiating a WebAssembly module or component. This vulnerability is fixed in 36.0.8, 43.0.2, and 44.0.1.","published":"2026-05-14T14:54:32.975Z","modified":"2026-08-12T03:51:10.388761700Z","cvss":null,"epss":{"score":0.00319,"percentile":0.24479,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"wasmtime","fixedVersion":"36.0.8"},{"ecosystem":"crates.io","name":"wasmtime","fixedVersion":"43.0.2"}],"fix":null,"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44216.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:45341"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-44216"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44216.json"},{"type":"ADVISORY","url":"https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-p8xm-42r7-89xg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44216"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477467"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:10.388761700Z"}}