Description
Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.
Remediation
References
https://hackerone.com/reports/842462
Related Vulnerabilities
CVE-2023-39410 Vulnerability in maven package org.apache.avro:avro
CVE-2020-8137 Vulnerability in npm package uppy
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-hive
CVE-2021-43803 Vulnerability in npm package next
CVE-2021-21341 Vulnerability in maven package com.thoughtworks.xstream:xstream