id: PYSEC-2024-327 published: "2024-04-04T16:15:09.107Z" modified: "2026-07-13T05:52:32.049957Z" aliases: - CVE-2024-30266 - GHSA-75hq-h6g9-h4q5 details: wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this panic. This vulnerability has been patched in version 19.0.1. affected: - package: name: wasmtime ecosystem: PyPI purl: pkg:pypi/wasmtime ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: 19.0.0 versions: - 0.0.1 - 0.0.2 - 0.11.0 - 0.12.0 - 0.15.0 - 0.15.1 - 0.16.0 - 0.16.1 - 0.17.0 - 0.18.0 - 0.18.1 - 0.18.2 - 0.19.0 - 0.20.0 - 0.21.0 - 0.22.0 - 0.23.0 - 0.24.0 - 0.25.0 - 0.26.0 - 0.27.0 - 0.28.0 - 0.28.1 - 0.29.0 - 0.30.0 - 0.31.0 - 0.32.0 - 0.33.0 - 0.34.0 - 0.35.0 - 0.36.0 - 0.37.0 - 0.38.0 - 0.39.1 - 0.40.0 - 0.9.0 - 1.0.0 - 1.0.1 - 10.0.0 - 10.0.1 - 11.0.0 - 12.0.0 - 13.0.0 - 13.0.1 - 13.0.2 - 14.0.0 - 15.0.0 - 16.0.0 - 17.0.0 - 17.0.1 - 18.0.0 - 18.0.2 - 19.0.0 - 2.0.0 - 3.0.0 - 4.0.0 - 5.0.0 - 6.0.0 - 7.0.0 - 8.0.0 - 8.0.1 - 9.0.0 ecosystem_specific: {} references: - type: ADVISORY url: https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-75hq-h6g9-h4q5 - type: REPORT url: https://github.com/bytecodealliance/wasmtime/issues/8281 - type: FIX url: https://github.com/bytecodealliance/wasmtime/commit/7f57d0bb0948fa56cc950278d0db230ed10e8664 - type: FIX url: https://github.com/bytecodealliance/wasmtime/pull/8018 - type: FIX url: https://github.com/bytecodealliance/wasmtime/pull/8283 severity: - type: CVSS_V3 score: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H