Memory Exhaustion Vulnerability in vm2 Affects Multiple Projects
CVE-2026-92961
8.7HIGH
What is CVE-2026-92961?
The vulnerability in vm2 versions prior to 3.11.6 arises from inadequate enforcement of the buffer allocation limit on various array constructors. This oversight permits attackers to allocate an excessive amount of host memory, potentially leading to Denial of Service conditions through resource exhaustion. Attackers can exploit this flaw using V8 intrinsics to circumvent the intended buffer allocation restrictions and monopolize the host process memory.
Affected Version(s)
vm2 0 < 3.11.6
vm2 3.11.6
