VDB
Sign up
HIGH7.5

GHSA-frp9-2v6r-gj97

muhammara and hummus vulnerable to null pointer dereference on bad response object

Quick fix

GHSA-frp9-2v6r-gj97 — hummus: upgrade to the fixed version with the command below.

npm install hummus@1.0.111

Details

The package muhammara before 2.6.0 and the package hummus before 1.0.111 are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with invalid data.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/hummus
Introduced in: 1.0.0Fixed in: 1.0.111
Fixnpm install hummus@1.0.111
npm/muhammara
Introduced in: 0Fixed in: 2.6.0
Fixnpm install muhammara@2.6.0

References