Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.
https://github.com/knokbak/save-pixels-updated
https://github.com/knokbak/get-pixels-updated
https://github.com/advisories/GHSA-w7q9-p3jq-fmhm