CVE-2025-71330
published 2026-06-10CVE-2025-71330: image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.43%
34.7th percentile
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length field is 0, causing the while loop condition to remain true indefinitely.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devspaces | code-rhel9 | — | — |
| discovery | discovery-ui-rhel9 | — | — |
| gatekeeper | gatekeeper-rhel9 | — | — |
| grafana | grafana | — | — |
| image-size | image-size | — | — |
| image-size | image-size | 1.1.0 – 1.2.1 | — |
| image-size | image-size | 2.0.0 – 2.0.2 | — |
| rhoai | odh-workbench-codeserver-datascience-cpu-py312-rhel9 | — | — |
| rhtas | rekor-search-ui-rhel9 | — | — |
| satellite | iop-vulnerability-frontend-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
image-size: image-size: Denial of Service via crafted ICNS image buffer
vendor_redhat·2026-06-10·CVSS 7.5
CVE-2025-71330 [HIGH] CWE-835 image-size: image-size: Denial of Service via crafted ICNS image buffer
image-size: image-size: Denial of Service via crafted ICNS image buffer
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length field is 0, causing the while loop condition to remain true indefinitely.
A flaw was found in image-size. A remote attacker can exploit this vulnerability by providing a specially crafted ICNS image buffer. This malicious buffer, containing valid magic bytes and a zero-valued entry length, causes an infinite loop in the ICNS
GHSA
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer.
ghsa_unreviewed·2026-06-10
CVE-2025-71330 [HIGH] CWE-835 image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer.
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length field is 0, causing the while loop condition to remain true indefinitely.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-71330 fcitx5: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
bugzilla·2026-06-25·CVSS 7.5
CVE-2025-71330 [HIGH] CVE-2025-71330 fcitx5: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
CVE-2025-71330 fcitx5: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71330 fbthrift: image-size: Denial of Service via crafted ICNS image buffer [epel-all]
bugzilla·2026-06-25·CVSS 7.5
CVE-2025-71330 [HIGH] CVE-2025-71330 fbthrift: image-size: Denial of Service via crafted ICNS image buffer [epel-all]
CVE-2025-71330 fbthrift: image-size: Denial of Service via crafted ICNS image buffer [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This project only ships JavaScript code as part of the website, the files are not shipped in the binary RPMs
Bugzilla
CVE-2025-71330 cachelib: image-size: Denial of Service via crafted ICNS image buffer [epel-all]
bugzilla·2026-06-25·CVSS 7.5
CVE-2025-71330 [HIGH] CVE-2025-71330 cachelib: image-size: Denial of Service via crafted ICNS image buffer [epel-all]
CVE-2025-71330 cachelib: image-size: Denial of Service via crafted ICNS image buffer [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This project only ships JavaScript code as part of the website, the files are not shipped in the binary RPMs
Bugzilla
CVE-2025-71330 cachelib: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
bugzilla·2026-06-25·CVSS 7.5
CVE-2025-71330 [HIGH] CVE-2025-71330 cachelib: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
CVE-2025-71330 cachelib: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This project only ships JavaScript code as part of the website, the files are not shipped in the binary RPMs
Bugzilla
CVE-2025-71330 onnxruntime: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
bugzilla·2026-06-25·CVSS 7.5
CVE-2025-71330 [HIGH] CVE-2025-71330 onnxruntime: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
CVE-2025-71330 onnxruntime: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71330 fbthrift: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
bugzilla·2026-06-25·CVSS 7.5
CVE-2025-71330 [HIGH] CVE-2025-71330 fbthrift: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
CVE-2025-71330 fbthrift: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This project only ships JavaScript code as part of the website, the files are not shipped in the binary RPMs
Bugzilla
CVE-2025-71330 nodejs-aw-webui: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
bugzilla·2026-06-25·CVSS 7.5
CVE-2025-71330 [HIGH] CVE-2025-71330 nodejs-aw-webui: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
CVE-2025-71330 nodejs-aw-webui: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71330 h3: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
bugzilla·2026-06-25·CVSS 7.5
CVE-2025-71330 [HIGH] CVE-2025-71330 h3: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
CVE-2025-71330 h3: image-size: Denial of Service via crafted ICNS image buffer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-71330 image-size: image-size: Denial of Service via crafted ICNS image buffer
bugzilla·2026-06-10·CVSS 7.5
CVE-2025-71330 [HIGH] CVE-2025-71330 image-size: image-size: Denial of Service via crafted ICNS image buffer
CVE-2025-71330 image-size: image-size: Denial of Service via crafted ICNS image buffer
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length field is 0, causing the while loop condition to remain true indefinitely.
2026-06-10
Published