All the vulnerabilities related to the version 0.2.6 of the package
Denial of Service in canvas
Versions of canvas
prior to 1.6.10 are vulnerable to Denial of Service. Processing malicious JPEGs or GIFs could crash the node process.
Upgrade to version 1.6.10
Buffer overflow in canvas
A buffer overflow is present in canvas versions before 1.6.11, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image.