Allocation of Resources Without Limits or Throttling in pnpm - #VU153396

 

Allocation of Resources Without Limits or Throttling in pnpm - #VU153396

Published: October 6, 2026


Vulnerability identifier: #VU153396
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to consume excessive memory during package publication.

The vulnerability exists due to insufficient limits on memory consumption in pnpm publish tarball metadata handling when reading oversized manifests or README files from pre-built tarballs into memory. A remote attacker can supply a pre-built tarball containing such files to consume excessive memory during package publication.


Affected software

pnpm

Remediation

Install security update from vendor's website.

pnpm - addressed in versions 11.28.5, 12.10.0

External References

Related Security Bulletins