CVE-2026-92947
vm2 shared Buffer pool host-memory exposure (version advisory)
- Severity
- critical
- Affected product
- vm2
- Affected versions
- vm2 ≤ 3.11.6
- Fixed in
- vm2 3.11.7
- Added to NewScan
- 2026-09-18
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints vm2 from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-18. Version source: exact vm2 pins in package.json, package-lock.json or yarn.lock, parsed by mine_versions and joined by the pack-derived alias map. A dependency-version advisory only; sandbox use and host-memory exposure are not confirmed. Maintainer range and fix: https://github.com/patriksimek/vm2/security/advisories/GHSA-fcqc-726x-5wfc (<=3.11.6; fixed 3.11.7). CVE association comes from the scheduler's saved NVD triage; the maintainer page has no CVE assigned. No sandbox payload is executed.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →