Stream: git-wasmtime

Topic: wasmtime / PR #12652 Fix two security advisories.


view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 16:34):

alexcrichton requested wasmtime-wasi-reviewers for a review on PR #12652.

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 16:34):

alexcrichton opened PR #12652 from alexcrichton:wasi-resource-limits to bytecodealliance:main:

This commit contains merged fixes for two security advisories in Wasmtime:

This introduces new knobs to Wasmtime to limit the scope of resources that WASI implementations will allocate on behalf of guests. Unlike backports to 41.0.x-and-prior these knobs all have default values which are considered reasonable for hosts if they don't further tune them. The following CLI knobs have been added:

The http crate has additionally been updated to avoid a panic when adding too many headers to a fields object.

<!--
Please make sure you include the following information:

Our development process is documented in the Wasmtime book:
https://docs.wasmtime.dev/contributing-development-process.html

Please ensure all communication follows the code of conduct:
https://github.com/bytecodealliance/wasmtime/blob/main/CODE_OF_CONDUCT.md
-->

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 16:34):

alexcrichton requested cfallin for a review on PR #12652.

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 16:34):

alexcrichton requested wasmtime-core-reviewers for a review on PR #12652.

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 16:39):

dicej submitted PR review.

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 16:45):

alexcrichton updated PR #12652.

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 16:48):

alexcrichton updated PR #12652.

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 16:53):

alexcrichton closed without merge PR #12652.

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 16:53):

alexcrichton reopened PR #12652 from alexcrichton:wasi-resource-limits to bytecodealliance:main.

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 16:53):

alexcrichton has enabled auto merge for PR #12652.

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 17:06):

alexcrichton updated PR #12652.

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 18:24):

alexcrichton added PR #12652 Fix two security advisories. to the merge queue

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 19:02):

alexcrichton merged PR #12652.

view this post on Zulip Wasmtime GitHub notifications bot (Feb 24 2026 at 19:02):

alexcrichton removed PR #12652 Fix two security advisories. from the merge queue


Last updated: Mar 23 2026 at 16:19 UTC