CVE-2025-71319
published 2026-06-09CVE-2025-71319: image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.64%
46.4th percentile
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devspaces | code-rhel9 | — | — |
| discovery | discovery-ui-rhel9 | — | — |
| gatekeeper | gatekeeper-rhel9 | — | — |
| grafana | grafana | — | — |
| image-size | image-size | <= 2.0.2 | — |
| image-size | image-size | — | — |
| image-size | image-size | 1.1.0 – 1.2.1 | — |
| image-size | image-size | 2.0.0 – 2.0.2 | — |
| rhtas | rekor-search-ui-rhel9 | — | — |
| satellite | iop-vulnerability-frontend-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
image-size up to 1.2.0/2.0.1 Image findBox infinite loop (GHSA-m5qc-5hw7-8vg7)
vuldb·2026-06-16·CVSS 7.5
CVE-2025-71319 [HIGH] image-size up to 1.2.0/2.0.1 Image findBox infinite loop (GHSA-m5qc-5hw7-8vg7)
A vulnerability categorized as problematic has been discovered in image-size up to 1.2.0/2.0.1. Affected by this issue is the function findBox of the component Image Handler. Such manipulation leads to infinite loop. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is documented as CVE-2025-71319. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
Red Hat
image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images.
vendor_redhat·2026-06-09·CVSS 7.5
CVE-2025-71319 [HIGH] CWE-835 image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images.
image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images.
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
A flaw was found in image-size. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by supplying specially crafted JXL, HEIF, or JP2 image files that contain zero-sized boxes. The `findBox` function, respons
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-71319 nodejs-aw-webui: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
bugzilla·2026-06-23·CVSS 7.5
CVE-2025-71319 [HIGH] CVE-2025-71319 nodejs-aw-webui: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
CVE-2025-71319 nodejs-aw-webui: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71319 fbthrift: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
bugzilla·2026-06-23·CVSS 7.5
CVE-2025-71319 [HIGH] CVE-2025-71319 fbthrift: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
CVE-2025-71319 fbthrift: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71319 fcitx5: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
bugzilla·2026-06-23·CVSS 7.5
CVE-2025-71319 [HIGH] CVE-2025-71319 fcitx5: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
CVE-2025-71319 fcitx5: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71319 cachelib: image-size: Denial of Service due to infinite loop when processing specially crafted images. [epel-all]
bugzilla·2026-06-23·CVSS 7.5
CVE-2025-71319 [HIGH] CVE-2025-71319 cachelib: image-size: Denial of Service due to infinite loop when processing specially crafted images. [epel-all]
CVE-2025-71319 cachelib: image-size: Denial of Service due to infinite loop when processing specially crafted images. [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71319 onnxruntime: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
bugzilla·2026-06-23·CVSS 7.5
CVE-2025-71319 [HIGH] CVE-2025-71319 onnxruntime: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
CVE-2025-71319 onnxruntime: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71319 h3: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
bugzilla·2026-06-23·CVSS 7.5
CVE-2025-71319 [HIGH] CVE-2025-71319 h3: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
CVE-2025-71319 h3: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71319 cachelib: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
bugzilla·2026-06-23·CVSS 7.5
CVE-2025-71319 [HIGH] CVE-2025-71319 cachelib: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
CVE-2025-71319 cachelib: image-size: Denial of Service due to infinite loop when processing specially crafted images. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71319 fbthrift: image-size: Denial of Service due to infinite loop when processing specially crafted images. [epel-all]
bugzilla·2026-06-23·CVSS 7.5
CVE-2025-71319 [HIGH] CVE-2025-71319 fbthrift: image-size: Denial of Service due to infinite loop when processing specially crafted images. [epel-all]
CVE-2025-71319 fbthrift: image-size: Denial of Service due to infinite loop when processing specially crafted images. [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71319 image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images.
bugzilla·2026-06-09·CVSS 7.5
CVE-2025-71319 [HIGH] CVE-2025-71319 image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images.
CVE-2025-71319 image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images.
image-size 1.1.0 before 1.2.1 and 2.0.0 before 2.0.2 contain a denial of service vulnerability in the findBox function when processing specially crafted images with zero-sized boxes. Remote attackers can cause application hang by supplying malicious JXL, HEIF, or JP2 image files with box size zero, triggering infinite loops during image validation.
https://joshua.hu/image-size-infinite-loop-dos-vulnerabilitieshttps://web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439https://www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-jxl-heif-parserhttps://access.redhat.com/errata/RHSA-2026:33313https://access.redhat.com/errata/RHSA-2026:37272https://access.redhat.com/security/cve/CVE-2025-71319https://bugzilla.redhat.com/show_bug.cgi?id=2487296https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-71319.json
2026-06-09
Published