Allocation of Resources Without Limits or Throttling in pnpm - #VU153396
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to consume excessive memory during package publication.
The vulnerability exists due to insufficient limits on memory consumption in pnpm publish tarball metadata handling when reading oversized manifests or README files from pre-built tarballs into memory. A remote attacker can supply a pre-built tarball containing such files to consume excessive memory during package publication.