A AegiFlow
HIGHCVSS 8.7EPSS 0.4%

CVE-2025-71329

image-size: JXL and HEIF parsers allow denial of service through infinite loops

Published
2026-06-10
Modified
2026-08-07
EPSS percentile
35%
Aliases
GHSA-5p2g-fcmc-qvqq
Sources
github-advisory

Summary

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmimage-size

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.