VDB
Sign up
MEDIUM

GHSA-vpq5-4rc8-c222

Denial of Service in canvas

Quick fix

GHSA-vpq5-4rc8-c222 — canvas: upgrade to the fixed version with the command below.

npm install canvas@1.6.10

Details

Versions of `canvas` prior to 1.6.10 are vulnerable to Denial of Service. Processing malicious JPEGs or GIFs could crash the node process.

## Recommendation

Upgrade to version 1.6.10

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/canvas
Introduced in: 0Fixed in: 1.6.10
Fixnpm install canvas@1.6.10

References