CVE-2026-44004
patriksimek vm2, Red Hat Developer Hub, Self-service automation portal 2 취약점
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory directly on the host heap. Because Buffer.alloc is a synchronous C++ native call, vm2's timeout option cannot interrupt it. A single request can exhaust host memory and crash the process with a FATAL ERROR: Reached heap limit. This vulnerability is fixed in 3.11.0.
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 0.42% 백분위 34.5% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.05.14