-
-
Notifications
You must be signed in to change notification settings - Fork 128
Closed
Description
Hey!
I noticed that the latest jpegoptim is vulnerable to pixel flood attack. Due to unlimited memory consumption, uploading a malicious jpg file to a web application that uses jpegoptim, may cause a denial of service.
You can read more on that vulnerability here.
Proof of concept
Metadata
Metadata
Assignees
Labels
No labels

