The Jpeg Js Project maintains a JavaScript-based JPEG decoder library with a narrow product scope but positioned as a foundational component within browser and web-application environments where image processing is integral. Observed vulnerabilities surface around the decoding pipeline's handling of malformed or edge-case JPEG structures; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jpeg Js Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25851HIGH The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return. | Jun 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-8175MEDIUM Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image. | Jul 24, 2020 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jpeg Js Project.
Media articles that mention a CVE ID that affects a product developed by Jpeg Js Project — matched by CVE ID, not by vendor name.