CVE Database
/

CVE-2025-62711

Back to search

CVE-2025-62711

Published: Oct 24, 2025

Modified: Oct 27, 2025

PUBLISHED

Description

Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which when called in a specific way, would crash the host with a segfault or assert failure. Wasmtime 38.0.3 has been released and is patched to fix this issue. There are no workarounds.

VendorProductVersions

bytecodealliance

wasmtime

affected
>= 38.0.0, < 38.0.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now