Allocation of Resources Without Limits or Throttling in pnpm - #VU153395
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to consume excessive memory while package metadata is processed.
The vulnerability exists due to insufficient limits on memory consumption in package manifest and archive metadata processing when reading oversized manifests or archive metadata during installation. A remote attacker can supply a package containing oversized metadata to consume excessive memory while package metadata is processed.