image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
History

Wed, 10 Jun 2026 14:30:00 +0000


Wed, 10 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Description image-size 1.1.0 before 1.2.1 and 2.0.0 before 2.0.2 contain a denial of service vulnerability in the findBox function when processing specially crafted images with zero-sized boxes. Remote attackers can cause application hang by supplying malicious JXL, HEIF, or JP2 image files with box size zero, triggering infinite loops during image validation. image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
Title image-size < 1.2.1, 2.0.2 - Denial of Service via Infinite Loop in findBox Function image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser
References

Wed, 10 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Image Sizes Project
Image Sizes Project image Sizes
Vendors & Products Image Sizes Project
Image Sizes Project image Sizes

Tue, 09 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Description image-size 1.1.0 before 1.2.1 and 2.0.0 before 2.0.2 contain a denial of service vulnerability in the findBox function when processing specially crafted images with zero-sized boxes. Remote attackers can cause application hang by supplying malicious JXL, HEIF, or JP2 image files with box size zero, triggering infinite loops during image validation.
Title image-size < 1.2.1, 2.0.2 - Denial of Service via Infinite Loop in findBox Function
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-06-09T19:57:16.125Z

Updated: 2026-06-10T12:55:58.825Z

Reserved: 2026-06-08T20:44:31.209Z

Link: CVE-2025-71319

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-09T21:17:03.153

Modified: 2026-06-10T14:16:30.010

Link: CVE-2025-71319

cve-icon Redhat

No data.