CVE-2026-9496
HighAdvisory
Published 26 May 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.7
- base score, highest
- EPSS
- 0.003
- 28th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 656
- of 17,787 indexed, latest versions
- Container images
- 669
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
pacote is vulnerable to Denial of Service (DoS) via the addGitSha function
Carried by container images the latest versions of 656 of 17,787 indexed charts deploy, on 669 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| npmdeb | 3.5.2-0ubuntu4, 6.14.4+ds-1ubuntu2, 9.2.0~ds1-2, 11.17.0-0 | no fix listed | 7 |
| pacotenpm | 11.2.7, 11.3.1, 11.3.3, 11.3.4+30 more | 21.5.1 | 663 |
Charts affected
656 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| verdacciowenerme | 4.35.1 | 1 of 1See more | 215 |
| wikiwikijs | 3.0.0 | 1 of 2See more | 5,459 |
| playwright-synthetic-monitoringwork-adventure | 1.0.1 | 1 of 1See more | 14,100 |
| workadventureworkadventure | 1.1.0 | 4 of 9See more | 16,083 |
| sockpuppetbrowserzekker6Verified publisher | 0.1.0 | 1 of 1See more | 1,589 |
| alertmanager-matrix-forwarderzloi-space | 1.0.1 | 1 of 2See more | 3,118 |
Container images carrying it
669 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.