High severity7.5NVD Advisory· Published Jun 10, 2026· Updated Jun 15, 2026
CVE-2025-71329
CVE-2025-71329
Description
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:image-size:image-size:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:image-size:image-size:*:*:*:*:*:*:*:*range: >=1.1.0,<=1.2.1
- (no CPE)range: <=2.0.2
Patches
Vulnerability mechanics
References
3- web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439nvdIssue TrackingPatch
- joshua.hu/image-size-infinite-loop-dos-vulnerabilitiesnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-jxl-heif-parsernvdThird Party Advisory
News mentions
0No linked articles in our index yet.