Memory Exhaustion Vulnerability in vm2 Affects Multiple Projects
CVE-2026-92961

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92961?

The vulnerability in vm2 versions prior to 3.11.6 arises from inadequate enforcement of the buffer allocation limit on various array constructors. This oversight permits attackers to allocate an excessive amount of host memory, potentially leading to Denial of Service conditions through resource exhaustion. Attackers can exploit this flaw using V8 intrinsics to circumvent the intended buffer allocation restrictions and monopolize the host process memory.

Affected Version(s)

vm2 0 < 3.11.6

vm2 3.11.6

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kr1shna4garwal
.