Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. boxlite
  4. ›
  5. CVE-2026-47213

CVE-2026-47213: BoxLite has a Timeout Bypass Vulnerability

May 29, 2026 (updated June 11, 2026)

BoxLite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. BoxLite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, BoxLite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, BoxLite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the BoxLite service.

References

  • github.com/advisories/GHSA-xjhv-pp2r-6f82
  • github.com/boxlite-ai/boxlite/commit/28159fc5b6b6fd5037e18a58fc4644c882e3c581
  • github.com/boxlite-ai/boxlite/security/advisories/GHSA-xjhv-pp2r-6f82
  • nvd.nist.gov/vuln/detail/CVE-2026-47213

Code Behaviors & Features

Detect and mitigate CVE-2026-47213 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 0.8.2

Solution

Unfortunately, there is no solution available yet.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-404: Improper Resource Shutdown or Release

Source file

pypi/boxlite/CVE-2026-47213.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:23:26 +0000.