CVE-2026-92961

vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory. Attackers can bypass the buffer allocation cap by using these V8 intrinsics to exhaust host process memory and trigger out-of-memory conditions.
Configurations

No configuration.

History

17 Sep 2026, 14:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-17 14:18

Updated : 2026-09-17 14:18


NVD link : CVE-2026-92961

Mitre link : CVE-2026-92961

CVE.ORG link : CVE-2026-92961


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling