Allocation of Resources Without Limits or Throttling Affecting yara-x package, versions <1.16.0-r1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.32% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-YARAX-16540091
  • published8 May 2026
  • disclosed14 May 2026

Introduced: 8 May 2026

CVE-2026-44216  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade Chainguard yara-x to version 1.16.0-r1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream yara-x package and not the yara-x package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked on overflow. This overflow is possible to trigger, and thus panic, when a table with an extremely large size is allocated. This is possible with the WebAssembly memory64 proposal where tables can have sizes in the 64-bit range as opposed to the previous 32-bit range which would not overflow. The panic happens when attempting to create a very large table, such as when instantiating a WebAssembly module or component. This vulnerability is fixed in 36.0.8, 43.0.2, and 44.0.1.

CVSS Base Scores

version 3.1