Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-71330

Опубликовано: 10 июн. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length field is 0, causing the while loop condition to remain true indefinitely.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:image-size:image-size:*:*:*:*:*:*:*:*
Версия от 1.1.0 (включая) до 1.2.1 (включая)
cpe:2.3:a:image-size:image-size:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.0.2 (включая)

EPSS

Процентиль: 36%
0.0043
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 6.5
redhat
2 месяца назад

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length field is 0, causing the while loop condition to remain true indefinitely.

CVSS3: 7.5
github
2 месяца назад

image-size: ICNS parser allows denial of service through an infinite loop

EPSS

Процентиль: 36%
0.0043
Низкий

7.5 High

CVSS3

Дефекты

CWE-835
Уязвимость CVE-2025-71330