Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-93604

CVE-2026-93604: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.2

    High [CVE-2026-93604] Sandbox escape via `crypto.setFips ` function

    CVE-2026-93604Source published Source updated

    Sandbox escape via `crypto.setFips()` function. Red Hat rates this important (CVSS 7.2). Weakness: CWE-1100. Affected products named by the advisory: Red Hat Developer Hub; Self-service automation portal 2.

    Related products — impact not confirmed
    • Red Hat Developer Hub
    • Self-service automation portal 2
    Source-reported affected versions
    • 3.12.0
    Source-reported fixed versions
    • 3.12.1
    Mitigation guidance
    • This issue is fixed in vm2 version 3.12.1. Red Hat will provide updated versions of Developer Hub and Ansible Portal that include the fixed library version. Until updates are available, administrators can reduce the risk of sandbox escape attacks by implementing the following mitigations: 1. Review vm2 sandbox configurations to determine if the 'crypto' builtin is explicitly allowlisted for untrusted guest code (require.builtin: ['crypto']). If crypto access is not required for guest code functionality, remove it from the allowlist. 2. Restrict the sources from which untrusted code is accepted. Only allow code execution from authenticated, trusted users or verified sources. Implement code review processes for any scripts or plugins before they are executed in vm2 sandboxes. 3. Monitor for unexpected changes to the Node.js process FIPS mode. Log calls to crypto.getFips() before and after guest code execution to detect unauthorized FIPS mode modifications. 4. In FIPS-required environments, consider running vm2 sandboxes in separate isolated processes rather than in the same process as critical application components. Process-level isolation provides an additional security boundary beyond vm2's VM isolation. 5. Implement additional access controls and audit logging for any systems that accept and execute user-provided code, scripts, or plugins. 6. Upgrade to vm2 3.12.1 or later as soon as updated packages are available from Red Hat.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery