Skip to content
VulniPulse
Advisory severityHigh7.2Red Hat Linux

High [CVE-2026-93604] Sandbox escape via `crypto.setFips ` function

This high-severity Red Hat Linux advisory covers CVE-2026-93604; related products: Red Hat Developer Hub, Self-service automation portal 2.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-93604 Source published Source updated

VulniPulse record published Record updated

Related products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Sandbox escape via `crypto.setFips()` function. Red Hat rates this important (CVSS 7.2).

Weakness: CWE-1100.

Affected products named by the advisory: Red Hat Developer Hub; Self-service automation portal 2.

Affected versions
  • 3.12.0

Official advisory · high-confidence parse· fetched 8 days ago·verify at source

Fixed versions
  • 3.12.1

Official advisory · high-confidence parse· fetched 8 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • This issue is fixed in vm2 version 3.12.1. Red Hat will provide updated versions of Developer Hub and Ansible Portal that include the fixed library version. Until updates are available, administrators can reduce the risk of sandbox escape attacks by implementing the following mitigations: 1. Review vm2 sandbox configurations to determine if the 'crypto' builtin is explicitly allowlisted for untrusted guest code (require.builtin: ['crypto']). If crypto access is not required for guest code functionality, remove it from the allowlist. 2. Restrict the sources from which untrusted code is accepted. Only allow code execution from authenticated, trusted users or verified sources. Implement code review processes for any scripts or plugins before they are executed in vm2 sandboxes. 3. Monitor for unexpected changes to the Node.js process FIPS mode. Log calls to crypto.getFips() before and after guest code execution to detect unauthorized FIPS mode modifications. 4. In FIPS-required environments, consider running vm2 sandboxes in separate isolated processes rather than in the same process as critical application components. Process-level isolation provides an additional security boundary beyond vm2's VM isolation. 5. Implement additional access controls and audit logging for any systems that accept and execute user-provided code, scripts, or plugins. 6. Upgrade to vm2 3.12.1 or later as soon as updated packages are available from Red Hat.

Official advisory · high-confidence parse· fetched 8 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.