PT-2026-48232 · Npm · Image-Size

·

CVE-2025-71319

·

Published

2025-04-02

·

Updated

2026-08-18

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions image-size versions 1.1.0 through 1.2.0 image-size versions 2.0.0 through 2.0.1
Description A denial of service issue exists when processing specially crafted images with zero-sized boxes. Remote attackers can cause an application hang by supplying malicious JXL, HEIF, or JP2 image files with a box size of zero, which triggers an infinite loop during image validation. This occurs within the findBox() function because the offset variable is not updated when the box.size is zero.
Recommendations Update image-size versions 1.1.0 through 1.2.0 to version 1.2.1. Update image-size versions 2.0.0 through 2.0.1 to version 2.0.2. As a temporary workaround, restrict the processing of JXL, HEIF, and JP2 image files until the update is applied.

Exploit

Fix

DoS

Infinite Loop

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71319
GHSA-M5QC-5HW7-8VG7

Affected Products

Image-Size