← العودة للجدول
CVE-2026-47139
CVE-2026-47139 — vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM su
📅 2026-06-12
🟠 High 🔥 No NVD Vulnerability Vulnerability CVSS 8.6

📋 الوصف الكامل

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to http, https, http2, net, dgram, tls, dns, and dns/promises is blocked. However, Node.js also exposes underscored internal HTTP builtins such as _http_client and _http_server. These are not blocked when th

💻 الأنظمة المتأثرة

Node.js

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-47139

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v3.11.4

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←