CVE-2026-9496
pacote, org.webjars.npm:pacote
Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.
- CVSS
- 7.7
- EPSS
- 0.35% 26.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.26