image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application. | |
| Title | image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T14:46:07.985Z
Reserved: 2026-06-10T12:57:20.193Z
Link: CVE-2025-71329
Updated: 2026-06-10T14:46:04.665Z
Status : Received
Published: 2026-06-10T14:16:30.160
Modified: 2026-06-10T14:16:30.160
Link: CVE-2025-71329
No data.
OpenCVE Enrichment
Updated: 2026-06-10T14:45:32Z