canvas is vulnerable to Use-After-Free
19
Low Risk
Affected versions of this package are vulnerable to a use-after-free issue when initializing canvases with an invalid surface. Additionally, a potential memory leak exists while loading SVGs. These vulnerabilities can lead to crashes and system outages, making the package susceptible to Denial of Service (DoS) attacks by malicious actors.
You are affected if you are using a version that falls within the vulnerable range.
canvas is vulnerable to Use-After-Free in versions 2.0.0 - 2.11.2.
Upgrade the canvas library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant