VYPR

probe-image-size

by Nodeca

CVEs (1)

  • CVE-2026-104861HigOct 2, 2026
    risk 0.42cvss 7.5epss —

    probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans to the end of input when attacker-controlled data…