CVE-2026-47683
EUVD-2026-6046117.08.2026, 21:16
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an attacker-controlled length, allowing sandbox code to perform large synchronous host external-memory allocations that bypass the configured cap and can exhaust the host process. This issue is fixed in version 3.11.6.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Vulnerability Media Exposure