VYPR

Image Size

by Npm

CVEs (1)

  • CVE-2025-71330HigJun 10, 2026
    risk 0.49cvss 7.5epss

    image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued…