Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-71329

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.

A flaw was found in image-size. A remote attacker can exploit this vulnerability by providing a specially crafted image buffer that contains a zero-valued size field within a recognized box-type. This malicious input can trigger an infinite loop in the JXL or HEIF image parsers, leading to a permanent block of the Node.js event loop. The consequence is a Denial of Service (DoS), causing the application to become unresponsive.

Отчет

A flaw was found in the image-size npm package. A crafted image buffer with a zero-valued size field in a recognized box-type (JXL or HEIF) can trigger an infinite loop, permanently blocking the Node.js event loop and causing a denial of service.

Меры по смягчению последствий

Upgrade to a version of image-size that validates box size fields. As a workaround, validate image inputs before passing them to image-size, rejecting files with zero-length box entries.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Red Hat Build of Podman Desktoprh-podman-desktop.gitNot affected
Red Hat Discovery 2discovery/discovery-ui-rhel9Not affected
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 8grafana-pcpNot affected
Red Hat Fuse 7image-sizeFix deferred
Red Hat JBoss Enterprise Application Platform 7image-sizeFix deferred
Red Hat JBoss Enterprise Application Platform 8image-sizeFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packimage-sizeFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2487540image-size: image-size: Denial of Service via crafted image buffer with zero-valued size field

EPSS

Процентиль: 36%
0.0043
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.

CVSS3: 7.5
github
2 месяца назад

image-size: JXL and HEIF parsers allow denial of service through infinite loops

EPSS

Процентиль: 36%
0.0043
Низкий

6.5 Medium

CVSS3