The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "0.4.4"
}
]
}