Allocation of Resources Without Limits or Throttling in pnpm - #VU153395

 

Allocation of Resources Without Limits or Throttling in pnpm - #VU153395

Published: October 6, 2026


Vulnerability identifier: #VU153395
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to consume excessive memory while package metadata is processed.

The vulnerability exists due to insufficient limits on memory consumption in package manifest and archive metadata processing when reading oversized manifests or archive metadata during installation. A remote attacker can supply a package containing oversized metadata to consume excessive memory while package metadata is processed.


Affected software

pnpm

Remediation

Install security update from vendor's website.

pnpm - addressed in versions 11.28.5, 12.10.0

External References

Related Security Bulletins