Two vulnerabilities in Wasmtime's WebAssembly Component Model allow a malicious guest module to disrupt host processes by abusing string transcoding and custom realloc behavior. CVE-2026-35195 is an out-of-bounds write in the Fast Assembly Component Trampolines (FACT) compiler path: during string transcoding, Wasmtime fails to validate the memory offset returned by a guest component's exported realloc function, letting an attacker supply an arbitrary 32-bit offset and potentially trigger writes up to 4 GiB outside the intended guest linear memory region. In typical default deployments, the result is a host crash due to faults on unmapped memory protected by reserved address space and guard pages.
A second flaw, CVE-2026-34942, causes a deterministic denial of service when a malicious Component Model module returns a deliberately misaligned pointer from a custom realloc function during string transfer operations. When Wasmtime writes transcoded data to that invalid alignment, Rust panics and the process terminates. While CVE-2026-34942 is limited to process crashes, CVE-2026-35195 carries higher risk in environments with reduced memory reservations or disabled guard pages, where the out-of-bounds write may lead to host memory corruption rather than only denial of service.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A second Wasmtime vulnerability, CVE-2026-35195, was disclosed affecting the FACT compiler subsystem during Component Model string transcoding. By returning an arbitrary 32-bit offset from an exported realloc function, a malicious guest can cause writes far outside intended linear memory bounds, leading to denial of service and potentially host memory corruption in less protected deployments.
A vulnerability tracked as CVE-2026-34942 was disclosed in Wasmtime's Component Model string transcoding path. A malicious WebAssembly component can return a deliberately misaligned pointer from a custom realloc function, triggering a Rust panic and crashing the host process.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.