<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 09:14:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-372356</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-372356</link>
      <description>EUVD-2026-372356</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-372356</guid>
    </item>
    <item>
      <title>fkie_cve-2026-92942</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-92942</link>
      <description>&lt;p&gt;vm2 before 3.11.7 (affected versions &amp;lt;= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout only wraps the single call to _runScript() via doWithTimeout() in lib/vm.js, and FinalizationRegistry and WeakRef are exposed to sandboxed code unmodified (they are not among the hardened globals in lib/setup-sandbox.js). Sandboxed code can register a FinalizationRegistry cleanup callback against an object and then drop the only strong reference to it; vm.run() returns within the configured timeout, but when the V8 garbage collector later reclaims the object it invokes the sandboxed cleanup callback outside any vm2 timeout accounting. A busy loop in that callback blocks the host event loop for an unbounded period, resulting in denial of service. The time of invocation depends on the garbage collector (e.g. under memory pressure or with --expose-gc).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;vm2 before 3.11.7 (affected versions &amp;lt;= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout only wraps the single call to _runScript() via doWithTimeout() in lib/vm.js, and FinalizationRegistry and WeakRef are exposed to sandboxed code unmodified (they are not among the hardened globals in lib/setup-sandbox.js). Sandboxed code can register a FinalizationRegistry cleanup callback against an object and then drop the only strong reference to it; vm.run() returns within the configured timeout, but when the V8 garbage collector later reclaims the object it invokes the sandboxed cleanup callback outside any vm2 timeout accounting. A busy loop in that callback blocks the host event loop for an unbounded period, resulting in denial of service. The time of invocation depends on the garbage collector (e.g. under memory pressure or with --expose-gc).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-92942</guid>
    </item>
    <item>
      <title>GHSA-r4fx-v8hh-22mv — vm2: timeout Option Bypass via FinalizationRegistry Cleanup Callback (Unbounded Host Event-Loop Block)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r4fx-v8hh-22mv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Vulnerability Summary
 
vm2&amp;#39;s `VM({ timeout })` option is documented and relied upon as the mechanism that bounds how long sandboxed code may execute. In the current implementation, the timeout only wraps the single synchronous call to `VM#run()` (via `doWithTimeout` → `this._runScript(script)` in `lib/vm.js`). It does not, and structurally cannot, bound code that the V8 engine itself schedules to run *after* that call has already returned.
 
`FinalizationRegistry` and `WeakRef` are exposed to sandboxed code completely unmodified — they are not present anywhere in `lib/setup-sandbox.js`&amp;#39;s list of specially-wrapped/hardened globals (only `WeakMap`, `Promise`, `Proxy`, `Reflect`, etc. receive hardening there). Sandboxed code can register a `FinalizationRegistry` callback against an object it creates and immediately drops. `VM#run()` returns normally, well within the configured timeout, because registration is instant. At some later point — determined entirely by the V8 garbage collector, and forceable on demand by the host process (e.g. under memory pressure, or via `--expose-gc`) — the engine invokes the sandboxed cleanup callback directly. This invocation is **not** mediated by `doWithTimeout`, `Script.runInContext({timeout})`, or any other vm2 accounting mechanism, because it isn&amp;#39;t a new call to `VM#run()` at all — it&amp;#39;s the GC&amp;#39;s own native callback-invocation path.&lt;/p&gt;
&lt;p&gt;## Affected Code &amp;amp; Version
 
- **Repository:** `patriksimek/vm2`
- **Version tested:** `3.11.6` (commit `…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: vm2&lt;/p&gt;
&lt;p&gt;### Vulnerability Summary
 
vm2&amp;#39;s `VM({ timeout })` option is documented and relied upon as the mechanism that bounds how long sandboxed code may execute. In the current implementation, the timeout only wraps the single synchronous call to `VM#run()` (via `doWithTimeout` → `this._runScript(script)` in `lib/vm.js`). It does not, and structurally cannot, bound code that the V8 engine itself schedules to run *after* that call has already returned.
 
`FinalizationRegistry` and `WeakRef` are exposed to sandboxed code completely unmodified — they are not present anywhere in `lib/setup-sandbox.js`&amp;#39;s list of specially-wrapped/hardened globals (only `WeakMap`, `Promise`, `Proxy`, `Reflect`, etc. receive hardening there). Sandboxed code can register a `FinalizationRegistry` callback against an object it creates and immediately drops. `VM#run()` returns normally, well within the configured timeout, because registration is instant. At some later point — determined entirely by the V8 garbage collector, and forceable on demand by the host process (e.g. under memory pressure, or via `--expose-gc`) — the engine invokes the sandboxed cleanup callback directly. This invocation is **not** mediated by `doWithTimeout`, `Script.runInContext({timeout})`, or any other vm2 accounting mechanism, because it isn&amp;#39;t a new call to `VM#run()` at all — it&amp;#39;s the GC&amp;#39;s own native callback-invocation path.&lt;/p&gt;
&lt;p&gt;## Affected Code &amp;amp; Version
 
- **Repository:** `patriksimek/vm2`
- **Version tested:** `3.11.6` (commit `…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r4fx-v8hh-22mv</guid>
    </item>
    <item>
      <title>RHSA-2026:72712 — Red Hat Security Advisory: Ansible plug-ins for Red Hat Developer Hub Product Release Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:72712</link>
      <description>&lt;p&gt;multer: Multer: Denial of Service via aborted or malformed multipart uploads undici: undici: Denial of Service via unrequested WebSocket subprotocol vm2: vm2: Denial of Service due to memory allocation limit bypass urllib: urllib: Credential leakage via cross-origin redirects js-yaml: js-yaml: Denial of Service via crafted YAML documents immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations qs: qs: Denial of Service via improper validation in stringify function js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing compression: compression: Denial of Service via memory leak on premature response close multer: multer: Denial of Service via orphaned disk writes on aborted uploads isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function. adm-zip: adm-zip: Denial of Service via crafted ZIP archives with zero declared uncompressed size vm2: vm2: Denial of Service via timeout bypass in sandboxed code vm2: vm2: Sandbox escape via denylist bypass in NodeVM vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation vm2: vm2: Denial of Service via memory exhaustion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;multer: Multer: Denial of Service via aborted or malformed multipart uploads undici: undici: Denial of Service via unrequested WebSocket subprotocol vm2: vm2: Denial of Service due to memory allocation limit bypass urllib: urllib: Credential leakage via cross-origin redirects js-yaml: js-yaml: Denial of Service via crafted YAML documents immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations qs: qs: Denial of Service via improper validation in stringify function js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing compression: compression: Denial of Service via memory leak on premature response close multer: multer: Denial of Service via orphaned disk writes on aborted uploads isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function. adm-zip: adm-zip: Denial of Service via crafted ZIP archives with zero declared uncompressed size vm2: vm2: Denial of Service via timeout bypass in sandboxed code vm2: vm2: Sandbox escape via denylist bypass in NodeVM vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation vm2: vm2: Denial of Service via memory exhaustion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:72712</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2997 — vm2: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in vm2 ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Daten zu manipulieren, um einen Denial of Service Angriff durchzuführen und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2997</guid>
    </item>
  </channel>
</rss>
