CRITICAL 10.0 NVD
CVE-2026-92947
vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related alloca
vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.
References
- https://github.com/patriksimek/vm2/security/advisories/GHSA-fcqc-726x-5wfc
- https://www.vulncheck.com/advisories/vm2-before-3.11.7-memory-disclosure-via-buffer-pool
- https://github.com/patriksimek/vm2/security/advisories/GHSA-fcqc-726x-5wfc
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-09-17 via NVD.
Risk Timeline
CVE Disclosed2026-09-17 · -1 days ago
Remediation Resources
vulnfeed aggregates 12865 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.