CVE-2026-31808 is a denial of service vulnerability affecting the `file-type` library, specifically its ASF (WMV/WMA) parser, when processing crafted input with a zero-sized sub-header. This medium-severity flaw (CVSS 5.3) allows an unauthenticated attacker to remotely trigger an infinite loop, stalling the Node.js event loop with a small 55-byte payload. Applications using `file-type` prior to version 21.3.1 to detect untrusted files are susceptible. While no public exploit code or active exploitation has been observed, the vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0.0, < 21.3.1CPE matchmatch criteria | cpe:2.3:a:sindresorhus:file-type:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.