vm2 is vulnerable to Denial of Service
75
High Risk
Guest code can call Buffer.alloc with extremely large sizes and pressure host heap without hitting the same throttling patterns as network-bound work. That yields a memory exhaustion denial of service against the embedding process. The behavior is especially risky when operators assume timeouts protect them from huge allocations. A new bufferAllocLimit option lets embedders cap individual allocations as defense in depth.
You are affected if you are using a version that falls within the vulnerable range.
vm2 is vulnerable to Denial of Service in versions 0.0.1 - 3.10.5.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant