file-type
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting file-typepage 1 of 1
- CVE-2022-36313MEDIUMCVSS 5.5EG 5.5✓ Fixed in 17.1.32022-07-21
An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsi…
- CVE-2026-31808MEDIUMCVSS 5.3EG 5.3✓ Fixed in 21.3.12026-03-10
file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in the ASF (WMV/WMA) file type detection parser. When parsing a crafted input where an ASF sub-header has a size field of…
- CVE-2026-32630MEDIUMCVSS 5.3EG 5.3✓ Fixed in 21.3.22026-03-16
file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excessive memory growth during type detection in file-type when using fileTypeFromBuffer(), fileTypeFromBlob(), or fileTypeFr…
Check whether file-type is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for file-type CVEs against the assets you own.
Start Free Scan →