skuzmich opened issue #14452:
Test Case
repro.wat
(module (type $obj (struct)) (type $garbage (array (mut i32))) (tag $exn) (global $keep_garbage (mut (ref null $garbage)) (ref.null $garbage)) (global $root (mut (ref null $obj)) (ref.null $obj)) (func $collect_then_throw i32.const 100000 array.new_default $garbage global.set $keep_garbage i32.const 100000 array.new_default $garbage global.set $keep_garbage i32.const 100000 array.new_default $garbage global.set $keep_garbage throw $exn) (func (export "_start") (local $local (ref null $obj)) struct.new $obj local.set $local local.get $local global.set $root block $outer_handler try_table (catch $exn $outer_handler) block $skip_throw block $inner_handler try_table (catch $exn $inner_handler) br $skip_throw end end throw $exn end call $collect_then_throw end return end local.get $local global.get $root ref.eq i32.eqz if unreachable end) )Steps to Reproduce
$ wasmtime repro.watExpected Results
No output.
Exits with 0.Actual Results
Error: failed to run main module `repro.wat` Caused by: 0: failed to invoke command default 1: error while executing at wasm backtrace: 0: 0x8d - <unknown>!<wasm function 1> 2: wasm trap: wasm `unreachable` instruction executedVersions and Environment
wasmtime 49.0.1 (46c23a87d 2026-09-24)
Operating system: macOS
Architecture: Arm64
Extra Info
Other collectors work fine:
$ wasmtime -C collector=drc repro.wat $ wasmtime -C collector=null repro.watNode with V8 works fine:
$ wasm-tools --version wasm-tools 1.212.0 (1cf71f9a9 2024-06-27) $ node --version v26.10.0 $ wasm-tools parse repro.wat | node --experimental-wasm-exnref -e 'WebAssembly.instantiate(require("fs").readFileSync(0)).then(r=>{r.instance.exports._start();console.log("ok")})' ok
skuzmich added the bug label to Issue #14452.
skuzmich commented on issue #14452:
Also it is unclear from docs which collector should be ok to use:
https://docs.wasmtime.dev/api/wasmtime/enum.Collector.html#variant.Auto
Currently this always defaults to the copying collector, but the default value may change over time.
https://docs.wasmtime.dev/api/wasmtime/enum.Collector.html#variant.Copying
Note that this collector is still under construction and is not yet functional.
alexcrichton closed issue #14452:
Test Case
repro.wat
(module (type $obj (struct)) (type $garbage (array (mut i32))) (tag $exn) (global $keep_garbage (mut (ref null $garbage)) (ref.null $garbage)) (global $root (mut (ref null $obj)) (ref.null $obj)) (func $collect_then_throw i32.const 100000 array.new_default $garbage global.set $keep_garbage i32.const 100000 array.new_default $garbage global.set $keep_garbage i32.const 100000 array.new_default $garbage global.set $keep_garbage throw $exn) (func (export "_start") (local $local (ref null $obj)) struct.new $obj local.set $local local.get $local global.set $root block $outer_handler try_table (catch $exn $outer_handler) block $skip_throw block $inner_handler try_table (catch $exn $inner_handler) br $skip_throw end end throw $exn end call $collect_then_throw end return end local.get $local global.get $root ref.eq i32.eqz if unreachable end) )Steps to Reproduce
$ wasmtime repro.watExpected Results
No output.
Exits with 0.Actual Results
Error: failed to run main module `repro.wat` Caused by: 0: failed to invoke command default 1: error while executing at wasm backtrace: 0: 0x8d - <unknown>!<wasm function 1> 2: wasm trap: wasm `unreachable` instruction executedVersions and Environment
wasmtime 49.0.1 (46c23a87d 2026-09-24)
Operating system: macOS
Architecture: Arm64
Extra Info
Other collectors work fine:
$ wasmtime -C collector=drc repro.wat $ wasmtime -C collector=null repro.watNode with V8 works fine:
$ wasm-tools --version wasm-tools 1.212.0 (1cf71f9a9 2024-06-27) $ node --version v26.10.0 $ wasm-tools parse repro.wat | node --experimental-wasm-exnref -e 'WebAssembly.instantiate(require("fs").readFileSync(0)).then(r=>{r.instance.exports._start();console.log("ok")})' ok
alexcrichton commented on issue #14452:
Fixed at https://github.com/bytecodealliance/wasmtime/pull/14478
This ended up being a security issue, and if you find future GC-corruption-style issues we'd appreciate it if you report those as a security advisory first so we can evaluate to see if it's a security issue. Regardless though thanks for the report!
Last updated: Oct 11 2026 at 04:10 UTC