The package jpeg-js before 0.4.4 is vulnerable to Denial of Service (DoS) where a particular piece of input will cause the program to enter an infinite loop and never return.
{ "github_reviewed_at": "2022-06-17T01:00:49Z", "severity": "HIGH", "cwe_ids": [ "CWE-835" ], "github_reviewed": true, "nvd_published_at": "2022-06-10T20:15:00Z" }