VYPR

npm package

image-size

pkg:npm/image-size

Vulnerabilities (1)

  • CVE-2025-71319HigJun 9, 2026
    affected >= 1.1.0, < 1.2.1fixed 1.2.1

    image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loo