CVE-2026-32630 describes a denial-of-service vulnerability in the `sindresorhus/file-type` library, affecting versions 20.0.0 through 21.3.1. A crafted ZIP file can trigger excessive memory growth when processed by functions like `fileTypeFromBuffer()`, `fileTypeFromBlob()`, or `fileTypeFromFile()`, leading to resource exhaustion. Rated Medium with a CVSS score of 5.3 (AV:N/AC:L/A:L), this vulnerability has a network attack vector and low attack complexity, primarily impacting system availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this flaw. The issue is resolved in version 21.3.2 of the library.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20.0.0, < 21.3.2CPE matchmatch criteria | cpe:2.3:a:sindresorhus:file-type:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.