WebAssembly: incorrect response MIME type (expected application/wasm)
instantiateStreaming requires the response to be served as application/wasm. Servers that do not know the extension send application/octet-stream or, on a 404, text/html.
Quick fix
Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.
# Check what the server sends
curl -sI https://example.com/app.wasm | grep -i content-type
# nginx
types { application/wasm wasm; }
# Express
app.use(express.static('public', {
setHeaders: (res, p) => { if (p.endsWith('.wasm')) res.type('application/wasm'); }
}));
// Fallback that works regardless of MIME type
const bytes = await (await fetch('app.wasm')).arrayBuffer();
const { instance } = await WebAssembly.instantiate(bytes, imports);
How to diagnose WebAssembly errors
WebAssembly errors are precise about the layer that failed. A CompileError means the bytes are not a valid module: most often the file was served with the wrong MIME type, or an HTML error page was fetched instead of the .wasm file. A RuntimeError: memory access out of bounds means the module read or wrote outside its linear memory, which in a language like C or Rust is a genuine memory-safety bug caught by the sandbox.
If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.
- Check what the server actually returned. The wasm file must be served as
application/wasmfor streaming compilation, and a 404 HTML page produces a misleading magic-number error. - Validate the module offline with
wasm-validateand inspect it withwasm-objdump -xfrom the WABT toolkit. - For out-of-bounds errors, rebuild with sanitizers or debug assertions in the source language. The wasm runtime cannot tell you which source line was responsible without DWARF info.
- Confirm imports match: every function the module imports must be supplied by the host with the exact name and signature, or instantiation fails.
- Build with debug symbols and use the browser's DWARF support to step through original source rather than raw wasm.
Tools worth reaching for
wasm-validate / wasm-objdump (WABT)browser DWARF debuggingwasmtime --invokecurl -I (check MIME type)
Authoritative references
Primary documentation for this error, worth reading before applying any fix in production.
Related WebAssembly errors
- WebAssembly: Cannot enlarge memory arraysThe module asked for more linear memory than it was built to have. Emscripten fixes the heap…
- WebAssembly: CompileError - invalid magic / sectionThe .wasm file is not valid WebAssembly bytes. Often the server returned an HTML error page…
- WebAssembly: null function or function signature mismatchAn indirect call went through the function table and found an empty slot, or a function whose…
- WebAssembly: RuntimeError - memory access out of boundsWASM code accessed memory outside its linear memory, usually from an out-of-bounds index…
- WebAssembly: RuntimeError: unreachable executedThe module reached an `unreachable` instruction, which compilers emit wherever the program…
- WebAssembly: SharedArrayBuffer is not definedThreaded builds need shared memory, and browsers only expose SharedArrayBuffer to cross…
Browse other categories
- HTTP 494xx client errors, 5xx server errors, redirects, headers and protocol problems.
- JavaScript 42npm resolution, async pitfalls, hydration, memory limits and runtime type…
- Database 41Connections, deadlocks, constraints, replication and memory limits.
- AI 35Rate limits, context windows, GPU memory and model-serving failures.
- Network 35Refused connections, timeouts, resets, MTU problems and port exhaustion.
- Python 35Imports, virtual environments, encoding, concurrency and dependency conflicts.
- Kubernetes 34CrashLoopBackOff, ImagePullBackOff, OOMKilled, RBAC, scheduling and storage.
- Docker 27Daemon connectivity, disk space, image pulls, ports and architecture mismatches.
- System 26Disk space, systemd units, file descriptors, OOM killer and scheduled jobs.
- Cloud 25IAM permissions, quotas, service limits and credential failures.
- Security 25JWT validation, CSRF, OAuth grants, SELinux, SSH host keys and CSP.
- TLS 24Untrusted authorities, expiry, hostname mismatch, chains and cipher negotiation.
Something missing or wrong?
This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.