CVE-2022-41957

Source
https://cve.org/CVERecord?id=CVE-2022-41957
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-41957.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-41957
Aliases
Published
2022-11-28T00:00:00Z
Modified
2025-11-28T05:01:48.445820Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
muhammara vulnerable to Unchecked Return Value to NULL Pointer Dereference
Details

Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara before 2.6.2 and from 3.0.0 and before 3.3.0, as well as all versions of muhammara's predecessor package hummus, are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed. The issue has been patched in muhammara version 3.4.0 and the fix has been backported to version 2.6.2. As a workaround, do not process files from untrusted sources. If using hummus, replace the package with muhammara.

Database specific
{
    "cwe_ids": [
        "CWE-690"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41957.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/julianhille/muhammarajs

Affected ranges

Type
GIT
Repo
https://github.com/julianhille/muhammarajs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.6.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/julianhille/muhammarajs
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.4.0"
        }
    ]
}

Affected versions

1.*
1.0.0
1.0.0-rc.1
1.0.0-rc.2
1.0.1
1.1.0
1.10.0
1.2.0
1.2.0-rc.1
1.3.0
1.4.0
1.4.1
1.4.2
1.4.3
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.9.0
2.*
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
3.*
3.0.0
3.1.0
3.1.1
3.2.0
3.3.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-41957.json"