CVE-2026-9496
HighAdvisory
Published 26 May 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.7
- base score, highest
- EPSS
- 0.003
- 28th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 663
- of 17,781 indexed, latest versions
- Container images
- 677
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
pacote is vulnerable to Denial of Service (DoS) via the addGitSha function
Carried by container images the latest versions of 663 of 17,781 indexed charts deploy, on 677 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| npmdeb | 3.5.2-0ubuntu4, 6.14.4+ds-1ubuntu2, 9.2.0~ds1-2, 11.17.0-0 | no fix listed | 7 |
| pacotenpm | 11.2.7, 11.3.1, 11.3.3, 11.3.4+30 more | 21.5.1 | 671 |
Charts affected
663 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| voteappvoting-app-helm-charts-repo-cloudVerified publisher | 1.0.0 | 1 of 5See more | 8,262 |
| websitewaldo-visionVerified publisher | 0.33.0 | 2 of 2See more | 3,474 |
| sirenwateim | 1.0.2 | 1 of 1See more | 5,984 |
| queryservice-gatewaywbstack | 0.2.0 | 1 of 1See more | 2,559 |
| webhookiewebhookie | 0.1.2 | 1 of 1See more | 14,364 |
| webhookie-allwebhookie | 0.1.2 | 1 of 3See more | 28,605 |
| apisix-ingress-controllerwenerme | 1.3.1 | 1 of 2See more | 1,616 |
| verdacciowenerme | 4.35.1 | 1 of 1See more | 215 |
| wikiwikijs | 3.0.0 | 1 of 2See more | 5,459 |
| playwright-synthetic-monitoringwork-adventure | 1.0.1 | 1 of 1See more | 14,100 |
| workadventureworkadventure | 1.1.0 | 4 of 9See more | 16,083 |
| sockpuppetbrowserzekker6Verified publisher | 0.1.0 | 1 of 1See more | 1,589 |
| alertmanager-matrix-forwarderzloi-space | 1.0.1 | 1 of 2See more | 3,118 |
Container images carrying it
677 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| hirosystems/ | 9c98b23c1515 | pacote | 21.5.1 | 1 |
| hkotel/ | 3c04c0e85039 | pacote | 21.5.1 | 1 |
| honglab/ | ca075a926fe1 | pacote | 21.5.1 | 1 |
| hoppscotch/ | 538fe6ded4b6 | pacote | 21.5.1 | 1 |
| hugohg34/ | 503e5d8960ff | pacote | 21.5.1 | 1 |
| ilum/ | 716437a51a6c | pacote | 21.5.1 | 1 |
| inseefrlab/ | 31f04ca7436b | pacote | 21.5.1 | 1 |
| instill/ | 4cd70e2df5c6 | pacote | 21.5.1 | 1 |
| instructure/ | 34400d82f28f | pacote | 21.5.1 | 1 |
| intelloop/ | 2409c2a00ab6 | pacote | 21.5.1 | 1 |
| interlayhq/ | 423d567d47aa | pacote | 21.5.1 | 1 |
| interlayhq/ | 5b2c414307b9 | pacote | 21.5.1 | 1 |
| jaedb/ | 048cfbf58d57 | pacote | 21.5.1 | 1 |
| jakowenko/ | b858bac9e32a | pacote | 21.5.1 | 1 |
| jedi132000/ | dc2a81e92f23 | pacote | 21.5.1 | 1 |
| jesec/ | 3d1d0bec117a | pacote | 21.5.1 | 1 |
| jesec/ | 60bd59cfb4eb | pacote | 21.5.1 | 1 |
| jesec/ | c887dad96b40 | pacote | 21.5.1 | 1 |
| jesec/ | f0c894ec459e | pacote | 21.5.1 | 1 |
| jhidalgo3/ | dfa8628d79f5 | pacote | 21.5.1 | 1 |
| jkroepke/ | 3d850992786d | pacote | 21.5.1 | 1 |
| johly/ | 9f702b91e0e7 | pacote | 21.5.1 | 1 |
| joplin/ | 52af57880c0e | pacote | 21.5.1 | 1 |
| joplin/ | b87564ef34e9 | pacote | 21.5.1 | 1 |
| josepht05/ | 36cb0c618c94 | pacote | 21.5.1 | 1 |
| josepht05/ | d94024965d78 | pacote | 21.5.1 | 1 |
| josh5/ | 4d49c4816260 | pacote | 21.5.1 | 1 |
| journeyapps/ | bf46f66e5dcc | pacote | 21.5.1 | 1 |
| jupyterhub/ | 3974ba945e65 | npm pacote | no fix listed 21.5.1 | 1 |
| kaushaln1/ | e9f2d5dfdba0 | pacote | 21.5.1 | 1 |
| keyoxide/ | 96f27a71269d | pacote | 21.5.1 | 1 |
| kobotoolbox/ | bcacc01bccd4 | pacote | 21.5.1 | 1 |
| ktitilayo2/ | 8bac28058688 | pacote | 21.5.1 | 1 |
| kubebb/ | 0fbb732379bc | pacote | 21.5.1 | 1 |
| kubebb/ | fd8ecbd73213 | pacote | 21.5.1 | 1 |
| kubeflownotebookswg/ | af55c22ef5de | pacote | 21.5.1 | 1 |
| kubevious/ | 2d9ba6eb46b6 | pacote | 21.5.1 | 1 |
| kubevious/ | f58226f9d84e | pacote | 21.5.1 | 1 |
| kubevious/ | 99ae7a5168c2 | pacote | 21.5.1 | 1 |
| kyleslugg/ | ba8c36dfdfbd | pacote | 21.5.1 | 1 |
| kyso/ | e52595c5c16f | pacote | 21.5.1 | 1 |
| laly9999/ | dd0e503913e1 | pacote | 21.5.1 | 1 |
| laly9999/ | 75ae77a20c6c | pacote | 21.5.1 | 1 |
| langgenius/ | bf8027ddccf3 | pacote | 21.5.1 | 1 |
| langgenius/ | dcefa5f7c47c | pacote | 21.5.1 | 1 |
| langgenius/ | 8dd9de6b6190 | pacote | 21.5.1 | 1 |
| langgenius/ | ba1dd1d0bcea | pacote | 21.5.1 | 1 |
| langgenius/ | 4e65e8a351a2 | pacote | 21.5.1 | 1 |
| langgenius/ | 87dd47e4e28f | pacote | 21.5.1 | 1 |
| langgenius/ | a2a294743634 | pacote | 21.5.1 | 1 |