Skip to main content

CVE-2026-104855: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in bytecodealliance wasmtime

0
Low
VulnerabilityCVE-2026-104855gcvecve-2026-104855cwe-362
Published: 10/02/2026 (10/02/2026, 17:37:50 UTC)
Source: GCVE Database
Vendor/Project: bytecodealliance
Product: wasmtime

Description

CVE-2026-104855 is a race condition vulnerability in the Wasmtime WebAssembly runtime affecting versions from 46.0.0 up to but not including 46.0.2 and from 47.0.0 up to but not including 47.0.3. The issue arises from improper synchronization during bulk operations like memory.copy, table.grow, and array.copy, which can expose invalid intermediate states when callbacks mutate or continue using a Store after cancellation or traps. This can lead to crashes, invalid memory access, or garbage collector heap corruption. Embeddings that only access host data or discard the Store after timeout are not affected. The vulnerability has a low CVSS score and is fixed in versions 46.0.2 and 47.0.3.

CVSS v4.0

Score 2.0low

Attack Vector
Network
Attack Complexity
High
Attack Requirements
Present
Privileges Required
High
User Interaction
Passive
Vuln. Confidentiality
None
Vuln. Integrity
Low
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected software

GitHub Actionsmore threats →ai
bytecodealliance/wasmtime
pkg:github/bytecodealliance/wasmtime
Affected versions
>=46.0.0 <46.0.2>=47.0.0 <47.0.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/02/2026, 20:02:23 UTC

Technical Analysis

Wasmtime versions >=46.0.0 <46.0.2 and >=47.0.0 <47.0.3 contain a race condition (CWE-362) in bulk operations involving fuel and epoch preemption checks. When an embedder mutates a Store during Store::epoch_deadline_callback or continues using a Store after cancellation or traps, invalid intermediate states can occur. Specific issues include cancelled non-nullable table growth leaving null elements, linear-memory growth invalidating retained raw pointers during memory.copy, and callback-triggered garbage collection invalidating GC pointers during array.copy. These conditions may cause crashes, invalid memory access, or GC heap corruption. Embeddings that only access host data or discard Stores after timeout are not vulnerable. The issue is resolved in versions 46.0.2 and 47.0.3.

Potential Impact

The vulnerability can cause application crashes, invalid memory accesses, or corruption of the garbage collector heap due to race conditions during bulk operations in Wasmtime. This may affect the stability and reliability of applications embedding Wasmtime under certain concurrency conditions. However, embeddings that do not mutate Stores during callbacks or discard Stores after timeout are not impacted. The CVSS score is low, indicating limited severity.

Mitigation Recommendations

This vulnerability is fixed in Wasmtime versions 46.0.2 and 47.0.3. Users should upgrade to these or later versions to remediate the issue. Embeddings that only access host data in Store<T> or discard Stores after timeout or epoch deadline are not affected and require no additional action.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-02T14:38:43.244Z
Cvss Version
4.0
State
PUBLISHED
Gcve Source
db.gcve.eu

Threat ID: 6ac00d29a43b0b3b89fb14b0

Added to database: 10/02/2026, 19:59:37 UTC

Last enriched: 10/02/2026, 20:02:23 UTC

Last updated: 10/03/2026, 02:46:20 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses