PT-2026-94332 · Npm · Vm2

·

CVE-2026-92961

·

Published

2026-08-14

·

Updated

2026-09-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.11.6
Description Failure to enforce the bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors allows attackers to allocate arbitrary host memory. While the bufferAllocLimit defense caps Buffer.alloc, Buffer.allocUnsafe, Buffer.allocUnsafeSlow, and new Buffer(N), it does not intercept V8 intrinsics such as Uint8Array or Float64Array. These constructors utilize the same underlying C++ allocation path as Buffer.alloc but bypass the size cap, enabling an attacker to exhaust host process memory and trigger out-of-memory (OOM) conditions. This can lead to a complete denial of service, particularly in memory-constrained environments like Docker containers, Kubernetes pods, and AWS Lambda.
Recommendations Update vm2 to version 3.11.6 or later. As a temporary workaround, restrict the use of ArrayBuffer, SharedArrayBuffer, and TypedArray constructors within the sandbox until the update is applied.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15026
CVE-2026-92961
GHSA-V836-6XW4-9CX3

Affected Products

Vm2