A AegiFlow
HIGHCVSS 8.7EPSS 0.4%

CVE-2025-71330

image-size: ICNS parser allows denial of service through an infinite loop

Published
2026-06-10
Modified
2026-08-07
EPSS percentile
35%
Aliases
GHSA-w3rx-r6r6-pgpr
Sources
github-advisory

Summary

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length field is 0, causing the while loop condition to remain true indefinitely.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmimage-size

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.