CVE-2022-25892

HIGH

muhammara < 2.6.1, 3.0.0-3.1.1 and hummus - Denial of Service via Malicious PDF Parsing

Title source: llm
STIX 2.1

Description

The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.

Scores

CVSS v3 7.5
EPSS 0.0256
EPSS Percentile 85.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

Status published
Products (5)
muhammara_project/muhammara
muhammara_project/muhammara 3.0.0
muhammara_project/muhammara 3.1.0
npm/hummus 0 - 1.0.111npm
npm/muhammara 0 - 2.6.1npm
Published Nov 01, 2022
Tracked Since Feb 18, 2026