{"id":"GHSA-xvf7-4v9q-58w6","summary":"Infinite loop in jpeg-js","details":"The package jpeg-js before 0.4.4 is vulnerable to Denial of Service (DoS) where a particular piece of input will cause the program to enter an infinite loop and never return.","aliases":["CVE-2022-25851"],"modified":"2025-01-14T10:56:51.595721Z","published":"2022-06-11T00:00:17Z","database_specific":{"nvd_published_at":"2022-06-10T20:15:00Z","cwe_ids":["CWE-835"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-06-17T01:00:49Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25851"},{"type":"WEB","url":"https://github.com/jpeg-js/jpeg-js/issues/105"},{"type":"WEB","url":"https://github.com/jpeg-js/jpeg-js/pull/106"},{"type":"WEB","url":"https://github.com/jpeg-js/jpeg-js/commit/9ccd35fb5f55a6c4f1902ac5b0f270f675750c27"},{"type":"PACKAGE","url":"https://github.com/jpeg-js/jpeg-js"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2860295"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-JPEGJS-2859218"}],"affected":[{"package":{"name":"jpeg-js","ecosystem":"npm","purl":"pkg:npm/jpeg-js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-xvf7-4v9q-58w6/GHSA-xvf7-4v9q-58w6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}