CVE-2025-71330
🟡 Monitoruj
Wersja image-size do 2.0.2 zawiera lukę, która pozwala na zdalne zablokowanie pętli zdarzeń Node.js.
CVSS
7.5
EPSS
0.4%
Exploit
poc
Vendor
image-size
Opis źródłowy (NVD)
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length field is 0, causing the while loop condition to remain true indefinitely.
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-06-10 14:16:30 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-05 16:10:00 UTC |
Referencje
- https://joshua.hu/image-size-infinite-loop-dos-vulnerabilities ([email protected]) [Exploit, Third Party Advisory]
- https://web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439 ([email protected]) [Issue Tracking, Patch]
- https://www.vulncheck.com/advisories/image-size-denial-of-service-via-malformed-icns-image-parsing ([email protected]) [Third Party Advisory]