Versions of canvas prior to 1.6.10 are vulnerable to Denial of Service. Processing malicious JPEGs or GIFs could crash the node process.
Upgrade to version 1.6.10
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2019-06-05T12:48:28Z",
"nvd_published_at": null,
"severity": "MODERATE"
}