View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2026-9496 severity important: SUSE including 30 source package names (cockpit, cockpit-bridge, …), 113 product×package rows across 12 product lines (SUSE Linux Enterprise Micro 5.3, SUSE Linux Enterprise Micro 5.4, … (12 product lines)): Known Not Affected 113.
Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function's regex replacement and string-manipulation logic, causing excessive CPU consumption and potentially stalling or crashing the process.