All the vulnerabilities related to the version 0.3.6 of the package
Uncontrolled resource consumption in jpeg-js
Uncontrolled resource consumption in jpeg-js before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.
Infinite loop in jpeg-js
The package jpeg-js before 0.4.4 is vulnerable to Denial of Service (DoS) where a particular piece of input will cause the program to enter an infinite loop and never return.
phin may include sensitive headers in subsequent requests after redirect
Users may be impacted if sending requests including sensitive data in specific headers with followRedirects enabled.
The follow-redirects library is now being used for redirects and removes some headers that may contain sensitive information in some situations.
N/A. Please update to resolve the issue.
semver vulnerable to Regular Expression Denial of Service
Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.