VulnerabilityModified
CVE-2022-25851
The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.
HIGH 7.5EPSS 1.85%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-835
- Affected
- jpeg-js project/jpeg-js
- Source
- report@snyk.io
References
- https://github.com/jpeg-js/jpeg-js/commit/9ccd35fb5f55a6c4f1902ac5b0f270f675750c27Patch, Third Party Advisory
- https://github.com/jpeg-js/jpeg-js/issues/105Exploit, Issue Tracking, Third Party Advisory
- https://github.com/jpeg-js/jpeg-js/pull/106/Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2860295Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-JPEGJS-2859218Third Party Advisory
- https://github.com/jpeg-js/jpeg-js/commit/9ccd35fb5f55a6c4f1902ac5b0f270f675750c27Patch, Third Party Advisory
- https://github.com/jpeg-js/jpeg-js/issues/105Exploit, Issue Tracking, Third Party Advisory
- https://github.com/jpeg-js/jpeg-js/pull/106/Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2860295Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-JPEGJS-2859218Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.