CVE-2025-71329
🟡 Monitoruj
Wersja image-size do 2.0.2 ma lukę, która pozwala na zdalne zablokowanie pętli zdarzeń Node.js.
CVSS
7.5
EPSS
0.4%
Exploit
poc
Vendor
image-size
Opis źródłowy (NVD)
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-06-10 14:16:30 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-05 16:10:00 UTC |
Referencje
- https://joshua.hu/image-size-infinite-loop-dos-vulnerabilities ([email protected]) [Exploit, Third Party Advisory]
- https://web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439 ([email protected]) [Issue Tracking, Patch]
- https://www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-jxl-heif-parser ([email protected]) [Third Party Advisory]