High severity7.5NVD Advisory· Published Jun 9, 2026· Updated Jun 15, 2026
CVE-2025-71319
CVE-2025-71319
Description
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
image-sizenpm | >= 1.1.0, < 1.2.1 | 1.2.1 |
image-sizenpm | >= 2.0.0, < 2.0.2 | 2.0.2 |
Affected products
3cpe:2.3:a:image-size:image-size:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:image-size:image-size:*:*:*:*:*:node.js:*:*range: <=2.0.2
- (no CPE)range: <1.2.0
Patches
Vulnerability mechanics
References
7- web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439nvdIssue TrackingPatchWEB
- joshua.hu/image-size-infinite-loop-dos-vulnerabilitiesnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-m5qc-5hw7-8vg7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-71319ghsaADVISORY
- www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-jxl-heif-parsernvdThird Party AdvisoryWEB
- github.com/image-size/image-size/commit/8994131c7c3ee8da1699e04700c95e0e683a0c68ghsaWEB
- github.com/image-size/image-size/security/advisories/GHSA-m5qc-5hw7-8vg7ghsaWEB
News mentions
0No linked articles in our index yet.