CVE-2026-9496

Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.
Configurations

No configuration.

History

27 Jun 2026, 16:16

Type Values Removed Values Added
Summary (en) Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process. (en) Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.
References
  • () https://github.com/npm/pacote/commit/ce804fb1647fe1699b2f87efd01ea9f4efed8508 -

26 May 2026, 14:16

Type Values Removed Values Added
CWE CWE-400
References () https://security.snyk.io/vuln/SNYK-JS-PACOTE-8225084 - () https://security.snyk.io/vuln/SNYK-JS-PACOTE-8225084 -

26 May 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 07:16

Updated : 2026-06-27 16:16


NVD link : CVE-2026-9496

Mitre link : CVE-2026-9496

CVE.ORG link : CVE-2026-9496


JSON object : View

Products Affected

No product.

CWE
CWE-1333

Inefficient Regular Expression Complexity

CWE-400

Uncontrolled Resource Consumption