image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser
Vulnerability Description
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71319
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Joshua Rogers (@MegaManSec)
References
Affected Vendor
image-size
View all reports →