Description
A buffer overflow is present in canvas versions before 1.6.11, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image.
Recommendation
Update the canvas package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.6.11
- Patched version(s): 1.6.11
References
Related Issues
- bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function - CVE-2025-3194
- Heap-based Buffer Overflow in sqlite-vec - CVE-2024-46488
- MJML vulnerable to path traversal - CVE-2020-12827
- Hostname spoofing via backslashes in URL - CVE-2020-26291
You might also like:
- Tags:
- npm
- canvas
Anything's wrong? Let us know Last updated on February 01, 2023


