CVE-2025-62711

Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which when called in a specific way, would crash the host with a segfault or assert failure. Wasmtime 38.0.3 has been released and is patched to fix this issue. There are no workarounds.
CVSS

No CVSS.

Configurations

No configuration.

History

24 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-24 22:15

Updated : 2025-10-24 22:15


NVD link : CVE-2025-62711

Mitre link : CVE-2025-62711

CVE.ORG link : CVE-2025-62711


JSON object : View

Products Affected

No product.

CWE
CWE-755

Improper Handling of Exceptional Conditions