Bug 2536034 (CVE-2026-92940) - CVE-2026-92940 vm2: vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent
Summary: CVE-2026-92940 vm2: vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via g...
Keywords:
Status: NEW
Alias: CVE-2026-92940
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-17 13:59 UTC by OSIDB Bzimport
Modified: 2026-09-30 10:16 UTC (History)
16 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-17 13:59:49 UTC
vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but method calls such as Agent.prototype.on() are forwarded to the underlying host object, so sandbox code can register a listener for the agent's 'free' event. When an unrelated host HTTPS request releases a pooled connection, the listener receives the live host request options and the host TLSSocket, allowing sandboxed code to read the host's Authorization header and private destination host/port, attach a data listener to the released socket and read subsequent host response bodies in plaintext, and issue attacker-chosen authenticated requests using the stolen credentials. The issue is fixed in 3.11.7.


Note You need to log in before you can comment on or make changes to this bug.