Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.
References
Configurations
No configuration.
History
26 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-400 | |
| References | () https://security.snyk.io/vuln/SNYK-JS-PACOTE-8225084 - |
26 May 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-26 07:16
Updated : 2026-05-26 20:16
NVD link : CVE-2026-9496
Mitre link : CVE-2026-9496
CVE.ORG link : CVE-2026-9496
JSON object : View
Products Affected
No product.
