VYPR
High severity7.5NVD Advisory· Published Jun 9, 2026· Updated Jun 15, 2026

CVE-2025-71319

CVE-2025-71319

Description

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
image-sizenpm
>= 1.1.0, < 1.2.11.2.1
image-sizenpm
>= 2.0.0, < 2.0.22.0.2

Affected products

3
  • cpe:2.3:a:image-size:image-size:*:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:image-size:image-size:*:*:*:*:*:node.js:*:*range: <=2.0.2
    • (no CPE)range: <1.2.0
  • ghsa-coords
    Range: >= 1.1.0, < 1.2.1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.