The Muhammara Project maintains a PDF-manipulation library with a narrow product footprint, whose vulnerabilities center on input-handling and error-checking weaknesses typical of document-processing codebases. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Muhammara Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25892HIGH The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted P | Nov 1, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-25885HIGH The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with invalid data. | Nov 1, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-41957HIGH Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara before 2.6.2 and from 3.0.0 and before 3.3.0, as well as al | Nov 28, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Muhammara Project.
Media articles that mention a CVE ID that affects a product developed by Muhammara Project — matched by CVE ID, not by vendor name.