VYPR
Medium severity5.7NVD Advisory· Published Apr 9, 2026· Updated Apr 20, 2026

CVE-2026-34944

CVE-2026-34944

Description

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabled Wasmtime's compilation of the f64x2.splat WebAssembly instruction with Cranelift may load 8 more bytes than is necessary. When signals-based-traps are disabled this can result in a uncaught segfault due to loading from unmapped guard pages. With guard pages disabled it's possible for out-of-sandbox data to be loaded, but this data is not visible to WebAssembly guests. This vulnerability is fixed in 24.0.7, 36.0.7, 42.0.2, and 43.0.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
wasmtimecrates.io
< 24.0.724.0.7
wasmtimecrates.io
>= 25.0.0, < 36.0.736.0.7
wasmtimecrates.io
>= 37.0.0, < 42.0.242.0.2
wasmtimecrates.io
>= 43.0.0, < 43.0.143.0.1

Affected products

10

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.