Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-64345

14
FAUCET Score

CVE-2025-64345 describes an unsound interaction in Wasmtime's Rust embedder API, affecting versions prior to 38.0.4, 37.0.3, 36.0.3, and 24.0.5. This vulnerability allows for a data race in the host due to shared WebAssembly linear memory being viewed as a safe type, despite parallel modifications. With a CVSS score of 1.8 (LOW), exploitation requires high privileges and user interaction, with a local attack vector, leading to a low impact on integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low current threat level.

Impacted Technologies

VendorProductVersion(s)CPE
BytecodeallianceWasmtime
< 24.0.5, >= 26.0.0, < 36.0.3, >= 37.0.0, < 37.0.3, >= 38.0.1, < 38.0.4CNA affected

CVSS Data

CVSS version used by this source: 3.1

1.8LOW

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
0.3
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 5th percentile among its peer group of 20 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

rustpatch availablevia ghsa
Product: wasmtimeFixed in: 38.0.4
rustpatch availablevia ghsa
Product: wasmtimeFixed in: 37.0.3
rustpatch availablevia ghsa
Product: wasmtimeFixed in: 36.0.3
rustpatch availablevia ghsa
Product: wasmtimeFixed in: 24.0.5
redhatvendor investigatingvia redhat_api
Product: Red Hat Connectivity Link 1Fixed in: rhcl-1/wasm-shim-rhel9

Vendor Advisories (2)

rustGHSA-hc7m-r6v8-hg9qlow

Wasmtime provides unsound API access to a WebAssembly shared linear memory

Nov 12, 2025
redhatCVE-2025-64345Low

wasmtime: Wasmtime unsound API access to shared linear memory

Nov 12, 2025

References

docs.rs / wasmtime/latest/wasmtime/struct.Memory.html
docs.rs / wasmtime/latest/wasmtime/struct.SharedMemory.html
docs.wasmtime.dev / stability-release.html
github.com / bytecodealliance/wasmtime/commit/9ebb6934f00d58b92fb68ed0e0b16c0ae828ca10
github.com / bytecodealliance/wasmtime/releases/tag/v38.0.4
github.com / bytecodealliance/wasmtime/security/advisories/GHSA-hc7m-r6v8-hg9q