CVE-2026-104855: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in bytecodealliance wasmtime
CVE-2026-104855 is a race condition vulnerability in the Wasmtime WebAssembly runtime affecting versions from 46.0.0 up to but not including 46.0.2 and from 47.0.0 up to but not including 47.0.3. The issue arises from improper synchronization during bulk operations like memory.copy, table.grow, and array.copy, which can expose invalid intermediate states when callbacks mutate or continue using a Store after cancellation or traps. This can lead to crashes, invalid memory access, or garbage collector heap corruption. Embeddings that only access host data or discard the Store after timeout are not affected. The vulnerability has a low CVSS score and is fixed in versions 46.0.2 and 47.0.3.
AI Analysis
Technical Summary
Wasmtime versions >=46.0.0 <46.0.2 and >=47.0.0 <47.0.3 contain a race condition (CWE-362) in bulk operations involving fuel and epoch preemption checks. When an embedder mutates a Store during Store::epoch_deadline_callback or continues using a Store after cancellation or traps, invalid intermediate states can occur. Specific issues include cancelled non-nullable table growth leaving null elements, linear-memory growth invalidating retained raw pointers during memory.copy, and callback-triggered garbage collection invalidating GC pointers during array.copy. These conditions may cause crashes, invalid memory access, or GC heap corruption. Embeddings that only access host data or discard Stores after timeout are not vulnerable. The issue is resolved in versions 46.0.2 and 47.0.3.
Potential Impact
The vulnerability can cause application crashes, invalid memory accesses, or corruption of the garbage collector heap due to race conditions during bulk operations in Wasmtime. This may affect the stability and reliability of applications embedding Wasmtime under certain concurrency conditions. However, embeddings that do not mutate Stores during callbacks or discard Stores after timeout are not impacted. The CVSS score is low, indicating limited severity.
Mitigation Recommendations
This vulnerability is fixed in Wasmtime versions 46.0.2 and 47.0.3. Users should upgrade to these or later versions to remediate the issue. Embeddings that only access host data in Store<T> or discard Stores after timeout or epoch deadline are not affected and require no additional action.
CVE-2026-104855: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in bytecodealliance wasmtime
Description
CVE-2026-104855 is a race condition vulnerability in the Wasmtime WebAssembly runtime affecting versions from 46.0.0 up to but not including 46.0.2 and from 47.0.0 up to but not including 47.0.3. The issue arises from improper synchronization during bulk operations like memory.copy, table.grow, and array.copy, which can expose invalid intermediate states when callbacks mutate or continue using a Store after cancellation or traps. This can lead to crashes, invalid memory access, or garbage collector heap corruption. Embeddings that only access host data or discard the Store after timeout are not affected. The vulnerability has a low CVSS score and is fixed in versions 46.0.2 and 47.0.3.
CVSS v4.0
Score 2.0low
Affected software
pkg:github/bytecodealliance/wasmtimeRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Wasmtime versions >=46.0.0 <46.0.2 and >=47.0.0 <47.0.3 contain a race condition (CWE-362) in bulk operations involving fuel and epoch preemption checks. When an embedder mutates a Store during Store::epoch_deadline_callback or continues using a Store after cancellation or traps, invalid intermediate states can occur. Specific issues include cancelled non-nullable table growth leaving null elements, linear-memory growth invalidating retained raw pointers during memory.copy, and callback-triggered garbage collection invalidating GC pointers during array.copy. These conditions may cause crashes, invalid memory access, or GC heap corruption. Embeddings that only access host data or discard Stores after timeout are not vulnerable. The issue is resolved in versions 46.0.2 and 47.0.3.
Potential Impact
The vulnerability can cause application crashes, invalid memory accesses, or corruption of the garbage collector heap due to race conditions during bulk operations in Wasmtime. This may affect the stability and reliability of applications embedding Wasmtime under certain concurrency conditions. However, embeddings that do not mutate Stores during callbacks or discard Stores after timeout are not impacted. The CVSS score is low, indicating limited severity.
Mitigation Recommendations
This vulnerability is fixed in Wasmtime versions 46.0.2 and 47.0.3. Users should upgrade to these or later versions to remediate the issue. Embeddings that only access host data in Store<T> or discard Stores after timeout or epoch deadline are not affected and require no additional action.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-02T14:38:43.244Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Gcve Source
- db.gcve.eu
Threat ID: 6ac00d29a43b0b3b89fb14b0
Added to database: 10/02/2026, 19:59:37 UTC
Last enriched: 10/02/2026, 20:02:23 UTC
Last updated: 10/03/2026, 02:46:20 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.