Your message dated Tue, 01 Sep 2026 09:19:55 +0000
with message-id <[email protected]>
and subject line Bug#1139159: fixed in npm 12.0.2+ds1-1
has caused the Debian Bug report #1139159,
regarding npm: CVE-2026-9496
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1139159: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139159
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: npm
Version: 11.16.0+ds2-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for npm.
CVE-2026-9496[0]:
| Versions of the package pacote from 11.2.7 are vulnerable to Denial
| of Service (DoS) via the addGitSha function. An attacker can exploit
| this vulnerability by supplying a specially crafted spec.rawSpec
| value that triggers the function’s regex replacement and string-
| manipulation logic, causing excessive CPU consumption and
| potentially stalling or crashing the process.
pacote is embedded/provided via src:npm.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-9496
https://www.cve.org/CVERecord?id=CVE-2026-9496
[1] https://security.snyk.io/vuln/SNYK-JS-PACOTE-8225084
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: npm
Source-Version: 12.0.2+ds1-1
Done: Xavier Guimard <[email protected]>
We believe that the bug you reported is fixed in the latest version of
npm, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated npm package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 01 Sep 2026 10:51:08 +0200
Source: npm
Architecture: source
Version: 12.0.2+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1139159
Changes:
npm (12.0.2+ds1-1) unstable; urgency=medium
.
* Team upload
* Exclude fastest-levenshtein, smart-buffer and socks-proxy-agent
* New upstream version (Closes: #1139159, CVE-2026-9496)
* Update patches
* Fix cmd-shim, fdir, ignore-walk, npm-normalize-package-bin, read-cmd-shim
install
* Update test
Checksums-Sha1:
16c27a13f07b574da8c98a38f734740d58d531f6 2632 npm_12.0.2+ds1-1.dsc
95b2ad0fb19122d3964f37d9f0fd2064bbe35c7c 68776936 npm_12.0.2+ds1.orig.tar.xz
17e7f08f17684b0146498cc3cef471383960f544 55104 npm_12.0.2+ds1-1.debian.tar.xz
Checksums-Sha256:
477cd318167343086eafa30954fde1f05e68a2cc25740798815d5f75248c3631 2632
npm_12.0.2+ds1-1.dsc
2cefc8d543dc3faf176e128e2e27c4cffc08f1ad815cf96ab2566f90d5bfb1f2 68776936
npm_12.0.2+ds1.orig.tar.xz
b6c42aac859a805a84f8369e44b5f64b6bb8995f94219f4f07526d5b6b7222ff 55104
npm_12.0.2+ds1-1.debian.tar.xz
Files:
a25824fee8b41660ca4bc0c75a47daa5 2632 javascript optional npm_12.0.2+ds1-1.dsc
26802c903a7c719c447b4bfe32532d72 68776936 javascript optional
npm_12.0.2+ds1.orig.tar.xz
39ff8585f4b5520b6b817bed651f62ee 55104 javascript optional
npm_12.0.2+ds1-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqWk64ACgkQ9tdMp8mZ
7ukwZg//akEc8v7EvTxDXFG6o0DQA71Yu0nwBQ9v2WVXWcgpV2KBfn7bGpkV7m6A
XixE6lrWN6oV7xGBhFCqMwKLsKKNOr/dp8R4mdlSCprWYO9L8xi/KB54ILzCjAEG
5Dj1pnxOV2qEPy5olySDpGhqX8X4ONc55kGHjqe6+Yt569wDrLzu1WN/CZimfCwy
goDu/33nnTfWK9zuPSKQfxi7lqmBQDW3ZPvWI0Pnn02AQiaSvcLmr0SxHbFljzR+
3rPcOc2gH51HWy1uOMj23035WtaQ4eB3flA/td8NXFqxy/jc+dnfzpEpZraK6NTV
5kaSzJkUnIBpHXqM3wveRamYK1/jfo9JFkUnkesxgIdTNB1/UDjqbNFty5wuVsEO
1YsBh23f/U3ajGHrWQJZ5lNah4p/zsUc40agbwssafIepPurWxqHlrwYLNivXY7c
PzB8U/e8OnQKq0aYx//6EenUlSMN/1e6gkqFw/U6wuCYqzgb5UNWcykjLic7UkXb
vlovCNSDz+VzBWHP1tndxCyHxDMA6qbCdCImlVpX69kDcBwcyZFwZd7PHOFL/SJy
+eqGZ+/2AdCZV1u0To73vSoBWm07Em1SK6PxgmGjgC3Xn6TIZ9w1FZBPdQauAzxN
8MiDlIZdx+6IXqeSLTMTZ/Dhkjo2AgPfVcyIz2HTwmn/hsCyBd0=
=7dmg
-----END PGP SIGNATURE-----
pgpnFW96Z781v.pgp
Description: PGP signature
--- End Message ---