« Volver al listado

CVE-2026-47213

Estado: AplazadaMedia (6.5)—

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, Boxlite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, Boxlite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the Boxlite service. This issue has been patched via commit 28159fc.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-47213",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-47213",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-11T12:53:07.688647Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "boxlite-ai",
          "product": "boxlite",
          "versions": [
            {
              "status": "affected",
              "version": "<= 0.8.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-10T23:16:48.323",
  "references": [
    {
      "url": "https://github.com/boxlite-ai/boxlite/commit/28159fc5b6b6fd5037e18a58fc4644c882e3c581",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/boxlite-ai/boxlite/security/advisories/GHSA-xjhv-pp2r-6f82",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/boxlite-ai/boxlite/security/advisories/GHSA-xjhv-pp2r-6f82",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-404"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, Boxlite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, Boxlite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the Boxlite service. This issue has been patched via commit 28159fc."
    },
    {
      "lang": "es",
      "value": "Boxlite es un servicio de sandbox que permite a los usuarios crear máquinas virtuales ligeras (Boxes) y lanzar contenedores OCI dentro de ellas para ejecutar código no confiable. En las versiones 0.8.2 y anteriores, Boxlite permite a los usuarios configurar un tiempo de espera para los servicios que se ejecutan dentro de la máquina virtual. Cuando se activa el tiempo de espera, Boxlite envía una señal para terminar el proceso. Sin embargo, en lugar de usar la señal SIGKILL no capturable, Boxlite usa la señal SIGALRM capturable. Código malicioso ejecutándose dentro del sandbox puede explotar esta vulnerabilidad para seguir ejecutándose después de que se active el tiempo de espera, lo que lleva al agotamiento de recursos dentro de la máquina virtual y afectando la disponibilidad del servicio Boxlite. Este problema ha sido parcheado a través del commit 28159fc."
    }
  ],
  "lastModified": "2026-07-23T09:10:00.113",
  "sourceIdentifier": "security-advisories@github.com"
}