An open index of dependabot pull requests across open source projects.

wasmtime

Ecosystem:
cargo
Package URL:
pkg:cargo/wasmtime
Total PRs:
427 Dependabot PRs
Latest PR:
10 days ago
Unique Repositories:
197 repositories
Unique Repos (30 days):
14 repositories
Security Advisories
Wasmtime has host panic when Winch compiler executes `table.fill`
GHSA-q49f-xg75-m9xw CVE-2026-34946 MODERATE published 2 months ago • updated 28 days ago
### Impact Wasmtime's Winch compiler contains a vulnerability where the compilation of the `table.fill` instruction can result in a host panic. Th...
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
GHSA-xx5w-cvp6-jv83 CVE-2026-34987 CRITICAL published about 2 months ago • updated about 7 hours ago
### Impact Wasmtime with its Winch (baseline) non-default compiler backend may allow properly constructed guest Wasm to access host memory outside...
Wasmtime: Panic when transcoding misaligned utf-16 strings
GHSA-jxhv-7h78-9775 CVE-2026-34942 MODERATE published 2 months ago • updated 10 days ago
### Impact Wasmtime's implementation of transcoding strings into the Component Model's `utf16` or `latin1+utf16` encodings improperly verified the...
Wasmtime has host data leakage with 64-bit tables and Winch
GHSA-m9w2-8782-2946 CVE-2026-34945 LOW published 2 months ago • updated 4 days ago
### Impact Wasmtime's Winch compiler contains a bug where a 64-bit table, part of the memory64 proposal of WebAssembly, incorrectly translated the...
Wasmtime has data leakage between pooling allocator instances
GHSA-6wgr-89rj-399p CVE-2026-34988 LOW published 2 months ago • updated about 1 hour ago
### Impact Wasmtime's implementation of its pooling allocator contains a bug where in certain configurations the contents of linear memory can be ...
Recent PRs
Package Details
Name: wasmtime
Ecosystem: cargo
PURL Type: cargo
Package URL: pkg:cargo/wasmtime
JSON API: View JSON
Security Advisories

39

Active advisories
CRITICAL 3
HIGH 2
MODERATE 21
LOW 13
View All cargo Advisories
Package Information
Description:

High-level API to expose the Wasmtime runtime

Repository: https://github.com/bytecodealliance/wasmtime
Latest Release: 30.0.2
over 1 year ago
Dependent Repos: 2,459
Dependent Packages: 180
Downloads: 11,366,529
Ranking: Top 0.7872% by dependent repos Top 0.9143% by downloads Top 0.5188% by dependent pkgs
PR Status
Open 168 (39.3%)
Merged 37 (8.7%)
Closed 197 (46.1%)
PR Types
Major 265 (62.1%)
Minor 1 (0.2%)
Patch 122 (28.6%)