← All CVEs NewScan detects
critical

CVE-2026-92947

vm2 shared Buffer pool host-memory exposure (version advisory)

Severity
critical
Affected product
vm2
Affected versions
vm2 ≤ 3.11.6
Fixed in
vm2 3.11.7
Added to NewScan
2026-09-18
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints vm2 from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-18. Version source: exact vm2 pins in package.json, package-lock.json or yarn.lock, parsed by mine_versions and joined by the pack-derived alias map. A dependency-version advisory only; sandbox use and host-memory exposure are not confirmed. Maintainer range and fix: https://github.com/patriksimek/vm2/security/advisories/GHSA-fcqc-726x-5wfc (<=3.11.6; fixed 3.11.7). CVE association comes from the scheduler's saved NVD triage; the maintainer page has no CVE assigned. No sandbox payload is executed.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →