Generated remediation guidance and an executive summary. No account required.
Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which when called in a specific way, would crash the host with a segfault or assert failure. Wasmtime 38.0.3 has been released and is patched to fix this issue. There are no workarounds.
Cite this page
CVE-2025-62711. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-62711
Use CWE-755, Bytecodealliance vendor hub and Wasmtime product page to widen CVE-2025-62711 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34987, CVE-2026-34971 and CVE-2026-34941 for nearby disclosures in the same product family.