🔐 CVE Alert

CVE-2026-9496

HIGH 7.5
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.

CWE CWE-1333
Vendor n/a
Product pacote
Published May 26, 2026
Last Updated May 26, 2026
Stay Ahead of the Next One

Get instant alerts for n/a pacote

Be the first to know when new high vulnerabilities affecting n/a pacote are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

n/a / pacote
11.2.7 < *
n/a / org.webjars.npm:pacote
11.2.7 < *

References

NVD ↗ CVE.org ↗ EPSS Data ↗
security.snyk.io: https://security.snyk.io/vuln/SNYK-JS-PACOTE-8225084 security.snyk.io: https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-16874025 github.com: https://github.com/npm/pacote/blob/9d7459440826ab4cf962ef98d8f3fd0c4d464b5c/lib/util/add-git-sha.js%23L2C1-L13C2

Credits

Rongchen Li