{"id":"CVE-2022-36313","title":"An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js","summary":"An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unrespon…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-835"],"vendor":"sindresorhus","product":"file-type","affected":["file-type < 16.5.4","file-type >= 17.0.0, < 17.1.3"],"patched":["file-type 17.1.3"],"published":"2022-07-21","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:17:30.503","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-36313","references":[{"url":"https://github.com/sindresorhus/file-type/releases/tag/v16.5.4","label":"cve@mitre.org"},{"url":"https://github.com/sindresorhus/file-type/releases/tag/v17.1.3","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20220909-0005/","label":"cve@mitre.org"},{"url":"https://www.npmjs.com/package/file-type","label":"cve@mitre.org"},{"url":"https://github.com/sindresorhus/file-type/releases/tag/v16.5.4","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/sindresorhus/file-type/releases/tag/v17.1.3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20220909-0005/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.npmjs.com/package/file-type","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T18:49:40.209210Z"},"epss":0.00406,"epssPercentile":0.32713,"ingestedAt":"2026-10-07T19:44:15.646Z","slug":"CVE-2022-36313","body":"## Overview\n\nAn issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file could cause the file type detector to get caught in an infinite loop. This would make the application become unresponsive and could be used to cause a DoS attack.\n\n## Affected\n\n- `file-type < 16.5.4`\n- `file-type >= 17.0.0, < 17.1.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `file-type 17.1.3`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}