{"id":"CVE-2022-25885","aliases":["GHSA-frp9-2v6r-gj97"],"url":"https://o3.security/vulnerability/CVE-2022-25885","summary":"Denial of Service (DoS)","details":"The package muhammara before 2.6.0 and the package hummus before 1.0.111 are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with invalid data.","published":"2022-11-01T05:05:18.156Z","modified":"2026-08-13T14:07:40.464293Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"hummus","fixedVersion":"1.0.111"},{"ecosystem":"npm","name":"muhammara","fixedVersion":"2.6.0"}],"fix":{"url":"https://github.com/julianhille/MuhammaraJS/commit/0a6427eec82ef2978995e453de2dc0d6224dd46c","label":"julianhille/MuhammaraJS@0a6427e"},"references":[{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-HUMMUS-3091139"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-MUHAMMARA-3091137"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25885.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25885"},{"type":"REPORT","url":"https://github.com/galkahana/HummusJS/issues/439"},{"type":"REPORT","url":"https://github.com/julianhille/MuhammaraJS/issues/188"},{"type":"FIX","url":"https://github.com/julianhille/MuhammaraJS/commit/0a6427eec82ef2978995e453de2dc0d6224dd46c"},{"type":"WEB","url":"https://github.com/galkahana/HummusJS/commit/a9bf2520ab5abb69f9328906e406fbebfb36159a"},{"type":"PACKAGE","url":"https://github.com/julianhille/MuhammaraJS"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-13T14:07:40.464293Z"}}