CVE-2026-47683
published 2026-08-17CVE-2026-47683: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list…
PriorityP353high8.7CVSS 4.0
AVNACLATNPRNUINVCNVINVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.39%
33.3th percentile
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an attacker-controlled length, allowing sandbox code to perform large synchronous host external-memory allocations that bypass the configured cap and can exhaust the host process. This issue is fixed in version 3.11.6.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform | automation-portal | — | — |
| ansible-automation-platform | bootc-automation-portal-rhel9 | — | — |
| patriksimek | vm2 | < 3.11.6 | 3.11.6 |
| rhdh | red-hat-developer-hub-backstage-plugin-lightspeed-backend | — | — |
| rhdh | red-hat-developer-hub-backstage-plugin-orchestrator-backend | — | — |
| rhdh | rhdh-hub-rhel9 | — | — |
| vm2_project | vm2 | >= 0 < 3.11.6 | 3.11.6 |
CVSS provenance
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
ghsa·2026-08-17
CVE-2026-47683 [HIGH] CWE-770 vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
## Summary
vm2 bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
The `bufferAllocLimit` option introduced in 3.11.0 (GHSA-6785-pvv7-mvg7) caps host-side Buffer allocations driven by sandbox code, the way embedders opt into `timeout`. The cap wraps `Buffer.alloc`, `Buffer.allocUnsafe`, `Buffer.allocUnsafeSlow`, and the deprecated `Buffer(N)` / `new Buffer(N)` forms. Two other API paths reach the same host C++ allocator with an attacker-controlled size and are not capped: `Buffer.concat(list, totalLength)` and `Buffer.from(arrayLike)` with a fake `length`. Sandbox code can use either to allocate an arbitrary number of host external bytes in a single call, defeating the explicit DoS mitiga
VulDB
patriksimek vm2 up to 3.11.5 Buffer Allocation Limit lib/setup-sandbox.js Buffer.concat allocation of resources (WID-SEC-2026-2865)
vuldb·2026-08-17·CVSS 8.7
CVE-2026-47683 [HIGH] patriksimek vm2 up to 3.11.5 Buffer Allocation Limit lib/setup-sandbox.js Buffer.concat allocation of resources (WID-SEC-2026-2865)
A vulnerability classified as problematic was found in patriksimek vm2 up to 3.11.5. Impacted is the function Buffer.concat of the file lib/setup-sandbox.js of the component Buffer Allocation Limit. The manipulation results in allocation of resources.
This vulnerability is known as CVE-2026-47683. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
Red Hat
vm2: vm2: Denial of Service due to memory allocation limit bypass
vendor_redhat·2026-08-17·CVSS 8.7
CVE-2026-47683 [HIGH] CWE-770 vm2: vm2: Denial of Service due to memory allocation limit bypass
vm2: vm2: Denial of Service due to memory allocation limit bypass
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an attacker-controlled length, allowing sandbox code to perform large synchronous host external-memory allocations that bypass the configured cap and can exhaust the host process. This issue is fixed in version 3.11.6.
A flaw was found in vm2, an open-source virtual machine (VM) sandbox for Node.js. This vulnerability allows malicious code running within the sandbox to bypass the configured memory allocation limit. By crafting specific calls to Buffer.concat or Buffer.from with attacker-controlled lengths, the sandbox code can
No detection rules found.
No public exploits indexed.
2026-08-17
Published