{"id":"RUSTSEC-2026-0327","summary":"Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow","details":"This is an entry in the RustSec database for the Wasmtime security advisory\nlocated at\nhttps://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-32h6-97mm-8q3c\nFor more information see the GitHub-hosted security advisory.","aliases":["GHSA-32h6-97mm-8q3c"],"modified":"2026-10-02T20:30:02.598161714Z","published":"2026-10-02T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/wasmtime"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0327.html"},{"type":"WEB","url":"https://github.com/bytecodealliance/wasmtime/pull/14471"}],"affected":[{"package":{"name":"wasmtime","ecosystem":"crates.io","purl":"pkg:cargo/wasmtime"},"ranges":[{"type":"SEMVER","events":[{"introduced":"39.0.0"},{"fixed":"48.0.4"},{"introduced":"49.0.0"},{"fixed":"49.0.2"}]}],"ecosystem_specific":{"affected_functions":null,"affects":{"functions":[],"arch":[],"os":[]}},"database_specific":{"categories":[],"cvss":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H","informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0327.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H"}]}