PT-2026-48232 · Npm · Image-Size
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
image-size versions 1.1.0 through 1.2.0
image-size versions 2.0.0 through 2.0.1
Description
A denial of service issue exists when processing specially crafted images with zero-sized boxes. Remote attackers can cause an application hang by supplying malicious JXL, HEIF, or JP2 image files with a box size of zero, which triggers an infinite loop during image validation. This occurs within the
findBox() function because the offset variable is not updated when the box.size is zero.Recommendations
Update image-size versions 1.1.0 through 1.2.0 to version 1.2.1.
Update image-size versions 2.0.0 through 2.0.1 to version 2.0.2.
As a temporary workaround, restrict the processing of JXL, HEIF, and JP2 image files until the update is applied.
Exploit
Fix
DoS
Infinite Loop
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Image-Size