THREAT OPS › Threat News › [GHSA] GHSA-gmc2-2x9w-cgh9 (high) — vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
[GHSA] GHSA-gmc2-2x9w-cgh9 (high) — vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
GHSA-gmc2-2x9w-cgh9 Severity: high CVE: CVE-2026-47683
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
## Summary
vm2 bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
The `bufferAllocLimit` option introduced in 3.11.0 (GHSA-6785-pvv7-mvg7) caps host-side Buffer allocations driven by sandbox code, the way embedders opt into `timeout`. The c
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-47683cve
Original source: https://github.com/advisories/GHSA-gmc2-2x9w-cgh9