CVE-2025-71319EPSS p40.5%
CVE-2025-71319CVE-2025-71319
image-size / image-size
Description
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.53% probability of exploitation · percentile 40.5% · 2026-06-18T12:00:27Z |
| Last modified | 2026-06-15 |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.