CVE-2026-92942
published 2026-09-17CVE-2026-92942: vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.34%
28.0th percentile
vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout only wraps the single call to _runScript() via doWithTimeout() in lib/vm.js, and FinalizationRegistry and WeakRef are exposed to sandboxed code unmodified (they are not among the hardened globals in lib/setup-sandbox.js). Sandboxed code can register a FinalizationRegistry cleanup callback against an object and then drop the only strong reference to it; vm.run() returns within the configured timeout, but when the V8 garbage collector later reclaims the object it invokes the sandboxed cleanup callback outside any vm2 timeout accounting. A busy loop in that callback blocks the host event loop for an unbounded period, resulting in denial of service. The time of invocation depends on the garbage collector (e.g. under memory pressure or with --expose-gc).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform | automation-portal | — | — |
| ansible-automation-platform | bootc-automation-portal-rhel9 | — | — |
| patriksimek | vm2 | < 3.11.7 | 3.11.7 |
| rhdh | red-hat-developer-hub-backstage-plugin-lightspeed-backend | — | — |
| rhdh | red-hat-developer-hub-backstage-plugin-orchestrator-backend | — | — |
| rhdh | rhdh-hub-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call.
ghsa_unreviewed·2026-09-17
CVE-2026-92942 [HIGH] CWE-400 vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call.
vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout only wraps the single call to _runScript() via doWithTimeout() in lib/vm.js, and FinalizationRegistry and WeakRef are exposed to sandboxed code unmodified (they are not among the hardened globals in lib/setup-sandbox.js). Sandboxed code can register a FinalizationRegistry cleanup callback against an object and then drop the only strong reference to it; vm.run() returns within the configured timeout, but when the V8 garbage collector later reclaims the object it invokes the sandboxed cleanup callback outside any vm2 timeout accounting. A busy loop in that callback blocks the host event loop for an unbounded period, resulting in denia
Red Hat
vm2: vm2: Denial of Service via timeout bypass in sandboxed code
vendor_redhat·2026-09-17·CVSS 7.5
CVE-2026-92942 [HIGH] CWE-1100 vm2: vm2: Denial of Service via timeout bypass in sandboxed code
vm2: vm2: Denial of Service via timeout bypass in sandboxed code
A flaw was found in vm2. Sandboxed code can bypass the configured timeout mechanism by using the FinalizationRegistry feature. This allows an attacker to execute a busy loop in a cleanup callback, which is invoked outside the timeout accounting. Consequently, this can block the host event loop indefinitely, leading to a Denial of Service (DoS) condition.
Statement: This is an Important denial of service vulnerability in vm2, affecting Red Hat Ansible Automation Platform and Red Hat Developer Hub. The flaw allows sandboxed code to bypass configured timeout mechanisms by exploiting the FinalizationRegistry feature, leading to an unbounded busy loop that can block the host event loop indefinitely. This can severely impact the
No detection rules found.
No public exploits indexed.
2026-09-17
Published