
Advisory documenting CVE-2026-78844, an uncontrolled resource consumption flaw in delight-nashorn-sandbox 0.5.5 where dynamic code evaluation bypasses maxCPUTime limits.
javadelight delight-nashorn-sandbox 0.5.5 suffers from Uncontrolled Resource Consumption. The sandbox enforces maxCPUTime limits by statically injecting interruption checks into JavaScript loops, but the sandbox fails to disable dynamic code evaluation. An attacker can use these functions to execute infinite loops that evade the static sanitizer.
Uncontrolled Resource Consumption,Protection Mechanism Failure
https://github.com/javadelight/delight-nashorn-sandbox - Version 0.5.5
an attacker must submit a crafted JavaScript payload to any application that uses Nashorn sandbox library for evaluation.
September 8th 2026