Количество 9
Количество 9
CVE-2026-9496
Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.
CVE-2026-9496
Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.
CVE-2026-9496
Versions of the package pacote from 11.2.7 and before 21.5.1 are vulne ...
GHSA-w4pp-8pjf-rmxw
Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.
SUSE-SU-2026:2695-1
Security update for nodejs22
SUSE-SU-2026:2647-1
Security update for nodejs22
openSUSE-SU-2026:21236-1
Security update for nodejs24
SUSE-SU-2026:2633-1
Security update for nodejs24
openSUSE-SU-2026:21058-1
Security update for nodejs22
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-9496 Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-9496 Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-9496 Versions of the package pacote from 11.2.7 and before 21.5.1 are vulne ... | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
GHSA-w4pp-8pjf-rmxw Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
SUSE-SU-2026:2695-1 Security update for nodejs22 | около 1 месяца назад | |||
SUSE-SU-2026:2647-1 Security update for nodejs22 | около 1 месяца назад | |||
openSUSE-SU-2026:21236-1 Security update for nodejs24 | 25 дней назад | |||
SUSE-SU-2026:2633-1 Security update for nodejs24 | около 1 месяца назад | |||
openSUSE-SU-2026:21058-1 Security update for nodejs22 | около 1 месяца назад |
Уязвимостей на страницу