CVE-2026-92961
published 2026-09-17CVE-2026-92961: vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.38%
31.4th percentile
vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory. Attackers can bypass the buffer allocation cap by using these V8 intrinsics to exhaust host process memory and trigger out-of-memory conditions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| patriksimek | vm2 | < 3.11.6 | 3.11.6 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory.
ghsa_unreviewed·2026-09-17
CVE-2026-92961 [HIGH] CWE-770 vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory.
vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory. Attackers can bypass the buffer allocation cap by using these V8 intrinsics to exhaust host process memory and trigger out-of-memory conditions.
Red Hat
vm2: vm2: Denial of Service via memory exhaustion
vendor_redhat·2026-09-17·CVSS 7.5
CVE-2026-92961 [HIGH] CWE-770 vm2: vm2: Denial of Service via memory exhaustion
vm2: vm2: Denial of Service via memory exhaustion
A flaw was found in vm2. This vulnerability allows an attacker to bypass the `bufferAllocLimit` enforcement on `ArrayBuffer`, `SharedArrayBuffer`, and `TypedArray` constructors. By doing so, the attacker can allocate arbitrary host memory, leading to memory exhaustion and a Denial of Service (DoS) condition for the affected system.
Statement: This is an Important denial of service vulnerability in vm2, a JavaScript sandbox. A remote attacker can bypass internal resource limits within the sandbox, allowing them to allocate arbitrary host memory. This can lead to the exhaustion of system resources and a denial of service for the host system running applications that utilize vm2 to execute untrusted code.
Mitigation: Mitigation for this iss
No detection rules found.
No public exploits indexed.
2026-09-17
Published