MODERATEcrates.io →
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
Affected packages
- wasmtime
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-xjhv-v822-pf94
- https://nvd.nist.gov/vuln/detail/CVE-2026-27195
- https://github.com/bytecodealliance/wasmtime/commit/9e51c0d9a240a9613d279c061f82286bd11383fd
- https://github.com/bytecodealliance/wasmtime/commit/d86b00736b9ece60b3c81e52f7a7e4cdd9f7d895
- https://bytecodealliance.zulipchat.com/#narrow/channel/206238-general/topic/.E2.9C.94.20Panic.20in.20Wasmtime.2041.2E0.2E3.20.28runtime.2Fconcurrent.2Fcomponent.29/with/574438798
- https://github.com/bytecodealliance/wasmtime
- https://github.com/bytecodealliance/wasmtime/releases/tag/v40.0.4
- https://github.com/bytecodealliance/wasmtime/releases/tag/v41.0.4
- https://rustsec.org/advisories/RUSTSEC-2026-0022.html
Structured record: https://osv.dev/vulnerability/GHSA-xjhv-v822-pf94
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta