{"id":"CVE-2022-25345","aliases":["GHSA-rvgf-69j7-xh78"],"url":"https://o3.security/vulnerability/CVE-2022-25345","summary":"Uncontrolled Resource Consumption in @discordjs/opus","details":"All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.","published":"2022-06-17T20:15:10Z","modified":"2026-04-10T04:45:56.261776Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"@discordjs/opus","fixedVersion":"0.8.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/discordjs/opus/blob/3ca4341ffdd81cf83cec57045e59e228e6017590/src/node-opus.cc%23L28"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-DISCORDJSOPUS-2403100"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-DISCORDJSOPUS-2403100"},{"type":"WEB","url":"https://github.com/discordjs/opus/blob/3ca4341ffdd81cf83cec57045e59e228e6017590/src/node-opus.cc%23L28"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T04:45:56.261776Z"}}