CVE Details
| CVE ID |
Severity |
Affected Package |
Installed Version |
Fixed Version |
Date Published |
Date of Scan |
| CVE-2026-9496 |
HIGH |
pacote |
19.0.2 |
21.5.1 |
2026-05-26T07:16:19.41Z |
2026-08-30T10:18:24.332625031Z |
Affected Docker Images
| Image Name |
SHA |
public.ecr.aws/lambda/nodejs:22 |
public.ecr.aws/lambda/nodejs@sha256:b3901afc920e44e82b151a46ed93c6bfd7126326fcfc2f53f905e737badaddb5 |
Description
Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.
Remediation Steps
- Update the affected package
pacote from version 19.0.2 to 21.5.1.
About this issue
- This issue may not contain all the information about the CVE nor the images it affects.
- This issue will not be updated with new information and the list of affected images may have changed since the creation of this issue.
- For more, visit Lambda Watchdog.
- This issue was created automatically by Lambda Watchdog.
CVE Details
HIGHpacote19.0.221.5.12026-05-26T07:16:19.41Z2026-08-30T10:18:24.332625031ZAffected Docker Images
public.ecr.aws/lambda/nodejs:22public.ecr.aws/lambda/nodejs@sha256:b3901afc920e44e82b151a46ed93c6bfd7126326fcfc2f53f905e737badaddb5Description
Remediation Steps
pacotefrom version19.0.2to21.5.1.About this issue