CVE-2026-9496Disclosure

LOWCVSS 7.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333CWE-400

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-26); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-26: 1Mentions · 2026-06-27: 1PoC Mentioned / Linked · 2026-06-27: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-26: 105-2606-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-9496](https://github.com/npm/pacote/blob/9d7459440826ab4cf962ef98d8f3fd0c4d464b5c/lib/u... https://github.com/npm/pacote/blob/9d7459440826ab4cf962ef98d8f3fd0c4d464b5c/lib/util/add-git-sha.js%23L2C1-L13C2 #Vulnerability #CVE #ZeroDay

    Post summary

    The post announces CVE‑2026‑9496 as a zero‑day vulnerability and supplies a direct link to the affected code in the npm/pacote library, indicating a new disclosure of the issue.

    0000043
    6 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - npm pacote ReDoS in Git Spec Parsing (CVE-2026-9496) The addGitSha function in pacote, npm's package-fetching library, can be stalled indefinitely by a crafted spec.rawSpec, pinning a CPU core, and crashing the process. Unauthenticated and network-reachable wherever pacote consumes user-controlled specs (CVSS 7.5). 👉 Affected: `pacote` (npm) ≥ 11.2.7 | No fix released. Validate package specs before passing them to pacote.

    Post summary

    The post discloses a CPU‑stalling ReDoS vulnerability in npm pacote, provides technical details and a recommended mitigation, but does not mention any PoC, exploit code, or active exploitation.

    00000104
    196 followersView on X

Explore more