THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gmc2-2x9w-cgh9 (high) — vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike

[GHSA] GHSA-gmc2-2x9w-cgh9 (high) — vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike

medgithub_advisoriesPublished 2026-08-17

GHSA-gmc2-2x9w-cgh9 Severity: high CVE: CVE-2026-47683

vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike

## Summary

vm2 bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike

The `bufferAllocLimit` option introduced in 3.11.0 (GHSA-6785-pvv7-mvg7) caps host-side Buffer allocations driven by sandbox code, the way embedders opt into `timeout`. The c

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gmc2-2x9w-cgh9