Denial of Service Vulnerability in Pacote Package by NPM
CVE-2026-9496

8.7HIGH

Key Information:

Vendor

NPM

Vendor
CVE Published:
26 May 2026

What is CVE-2026-9496?

The Pacote package from NPM is vulnerable to a Denial of Service attack through its addGitSha function. An attacker can exploit this weakness by delivering a specially crafted input to the spec.rawSpec variable. This input triggers the function’s regex replacement mechanism, leading to excessive CPU usage and risking the stability of the application by causing it to stall or crash. It is crucial for users of the affected versions to implement immediate updates to safeguard against potential exploits.

Affected Version(s)

org.webjars.npm:pacote 11.2.7

pacote 11.2.7

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rongchen Li
.