Denial of Service Vulnerability in Pacote Package by NPM
CVE-2026-9496
8.7HIGH
What is CVE-2026-9496?
The Pacote package from NPM is vulnerable to a Denial of Service attack through its addGitSha function. An attacker can exploit this weakness by delivering a specially crafted input to the spec.rawSpec variable. This input triggers the function’s regex replacement mechanism, leading to excessive CPU usage and risking the stability of the application by causing it to stall or crash. It is crucial for users of the affected versions to implement immediate updates to safeguard against potential exploits.
Affected Version(s)
org.webjars.npm:pacote 11.2.7
pacote 11.2.7
