GHSA-w4pp-8pjf-rmxw

Suggest an improvement
Source
https://github.com/advisories/GHSA-w4pp-8pjf-rmxw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-w4pp-8pjf-rmxw/GHSA-w4pp-8pjf-rmxw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w4pp-8pjf-rmxw
Aliases
Downstream
Related
Published
2026-05-26T13:30:54Z
Modified
2026-08-29T04:10:51.266075814Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
pacote is vulnerable to Denial of Service (DoS) via the addGitSha function
Details

Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.

Database specific
{
    "nvd_published_at": "2026-05-26T07:16:19Z",
    "github_reviewed_at": "2026-08-27T16:39:41Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-1333",
        "CWE-400"
    ]
}
References

Affected packages

npm / pacote

Package

Affected ranges

Type
SEMVER
Events
Introduced
11.2.7
Fixed
21.5.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-w4pp-8pjf-rmxw/GHSA-w4pp-8pjf-rmxw.json"