Allocation of Resources Without Limits or Throttling in pnpm - #VU153378

 

Allocation of Resources Without Limits or Throttling in pnpm - #VU153378

Published: October 6, 2026


Vulnerability identifier: #VU153378
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service through excessive memory consumption.

The vulnerability exists due to unrestricted memory allocation in archive metadata processing in pnpm install and pnpm publish when reading archive metadata into memory. A remote attacker can supply a tarball with oversized metadata that a victim installs or publishes to cause a denial of service through excessive memory consumption.

Publishing a pre-built tarball also processes oversized manifests and README files.


Affected software

pnpm

Remediation

Install security update from vendor's website.

pnpm - update to 12.10.0

External References

Related Security Bulletins