The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-25851.json"