CVE-2026-47683
vm2: bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an attacker-controlled length, allowing sandbox code to perform large synchronous host external-memory allocations that bypass the configured cap and can exhaust the host process. This issue is fixed in version 3.11.6.
| CWE | CWE-770 |
| Vendor | patriksimek |
| Product | vm2 |
| Published | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for patriksimek vm2
Be the first to know when new unknown vulnerabilities affecting patriksimek vm2 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
patriksimek / vm2
< 3.11.6