CVE-2022-23636 affects Wasmtime prior to versions 0.34.1 and 0.33.1. The flaw is in the runtime's pooling instance allocator: if instantiation fails for a WebAssembly module that defines an externref global, Wasmtime can attempt to drop a VMExternRef through an uninitialized pointer. In practice, this is a partially initialized object cleanup bug triggered during failed instance creation. The vulnerable path requires the pooling allocation strategy and a module using reference types/externref; additional conditions described by the advisory must also hold. The issue is tied to erroneous cleanup of incompletely initialized state rather than normal successful module execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
externref usage is uncommon and, absent a configured Store resource limiter, triggering generally depends on allocation/protection failures such as mprotect or VirtualAlloc errors. On Linux with the uffd feature enabled, triggering is limited to resource-limiter-driven scenarios because mprotect is skipped.If you can’t patch tonight, do this now.
Config::wasm_reference_types(false), which prevents loading modules that use externref. Exposure is also reduced by avoiding the pooling allocation strategy and using the default allocation strategy instead. In affected scenarios, not configuring a Store resource limiter further limits practical triggerability, though this is not a substitute for patching.Patch, then assume compromise.
wasmtime crate to 0.34.1, 0.33.1, or a later fixed release. These versions correct the invalid drop/uninitialized pointer handling in the pooling instance allocator.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, standalone authenticated RCE exploit for m1k1o's Blog, targeting CVE-2022-23626 despite the Python filename being inconsistently named cve-2022-23636.py. The repo contains only two files: one Python exploit script and one README with usage and vulnerability context. The exploit flow is straightforward: it first performs a GET to the supplied base URL to extract a PHPSESSID cookie and a CSRF token from the page content, then authenticates to /ajax.php using supplied credentials, then abuses the vulnerable /ajax.php?action=upload_image endpoint to upload a PHP webshell named shell.gif.php with a GIF89a magic header to bypass naive file validation. After upload, it requests the returned path directly to execute the payload. The payload supports two modes: arbitrary command execution supplied with --command, or a reverse shell using php -r with fsockopen to an attacker listener. This is a real exploit, not a detector, and it provides practical post-auth remote code execution against vulnerable deployments where uploaded PHP files are web-accessible and executable. The code is simple and operational, but not highly robust: error handling is minimal, token extraction is brittle string-splitting, and the trigger function appears syntactically incomplete in the provided content, though the intended behavior is clear from context and README.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.