Image-Size vulnerabilities
3 known vulnerabilities affecting image-size/image-size.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3
Vulnerabilities
Page 1 of 1
CVE-2025-71319P3HIGHCVSS 7.5≥ 1.1.0, ≤ 1.2.1≥ 2.0.0, ≤ 2.0.22026-06-09
CVE-2025-71319 [HIGH] CWE-835 CVE-2025-71319: image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing
nvd
CVE-2025-71330P3HIGHCVSS 7.5≥ 1.1.0, ≤ 1.2.1≥ 2.0.0, ≤ 2.0.22026-06-10
CVE-2025-71330 [HIGH] CWE-835 CVE-2025-71330: image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offse
nvd
CVE-2025-71329P3HIGHCVSS 7.5≥ 1.1.0, ≤ 1.2.1≥ 2.0.0, ≤ 2.0.22026-06-10
CVE-2025-71329 [HIGH] CWE-835 CVE-2025-71329: image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing
nvd