Sindresorhus maintains a narrowly scoped collection of lightweight utility libraries, with a notable concentration of exposure centered on the file_type product and its handling of compressed and binary data formats. The observed weakness classes—infinite-loop conditions and improper handling of highly compressed data—reflect the parsing and resource-consumption challenges inherent to format-detection logic. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sindresorhus over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36313MEDIUM An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infin | Jul 21, 2022 | 5.5 | 20 | NO | NO |
CVE-2026-31808MEDIUM file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in the ASF (WMV/WMA) file type detection parser. When parsing | Mar 10, 2026 | 5.3 | 19 | NO | NO |
CVE-2026-32630MEDIUM file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excessive memory growth during type detection in file-type when us | Mar 16, 2026 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sindresorhus.
Media articles that mention a CVE ID that affects a product developed by Sindresorhus — matched by CVE ID, not by vendor name.