Allocation of Resources Without Limits or Throttling in pnpm - #VU153378
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service through excessive memory consumption.
The vulnerability exists due to unrestricted memory allocation in archive metadata processing in pnpm install and pnpm publish when reading archive metadata into memory. A remote attacker can supply a tarball with oversized metadata that a victim installs or publishes to cause a denial of service through excessive memory consumption.
Publishing a pre-built tarball also processes oversized manifests and README files.