Description
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, Boxlite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, Boxlite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the Boxlite service. This issue has been patched via commit 28159fc.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/boxlite-ai/boxlite/security/advisories/GHSA-xjhv-pp2r-6f82
X_Refsource_Misc x_refsource_misc
https://github.com/boxlite-ai/boxlite/commit/28159fc5b6b6fd5037e18a58fc4644c882e3c581
Scores
CVSS v3
6.5
EPSS
0.0042
EPSS Percentile
33.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-404
Status
published
Products (2)
boxlite-ai/boxlite
<= 0.8.2
pypi/boxlite
0 - 0.8.2PyPI
Published
Jun 10, 2026
Tracked Since
Jun 11, 2026