image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-…
Summary
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
Lint boundary warnings (1)
The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://joshua.hu/image-size-infinite-loop-dos-vulnerabilities
Sources
- NVD DATABASE
Original Links
- https://joshua.hu/image-size-infinite-loop-dos-vulnerabilities Exploit
- https://web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439 Issue Tracking
- https://www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-jxl-heif-parser Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:33313 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:37272 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-71319 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2487296 Issue Tracking
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-71319.json Third Party Advisory
Timeline
- nvd_ingest NVD