image-size 1.1.0 before 1.2.1 and 2.0.0 before 2.0.2 contain a denial of service vulnerability in the findBox function when processing specially crafted images with zero-sized boxes. Remote attackers can cause application hang by supplying malicious JXL, HEIF, or JP2 image files with box size zero, triggering infinite loops during image validation.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m5qc-5hw7-8vg7 | image-size Denial of Service via Infinite Loop during Image Processing |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 09 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | image-size 1.1.0 before 1.2.1 and 2.0.0 before 2.0.2 contain a denial of service vulnerability in the findBox function when processing specially crafted images with zero-sized boxes. Remote attackers can cause application hang by supplying malicious JXL, HEIF, or JP2 image files with box size zero, triggering infinite loops during image validation. | |
| Title | image-size < 1.2.1, 2.0.2 - Denial of Service via Infinite Loop in findBox Function | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-09T19:57:16.125Z
Reserved: 2026-06-08T20:44:31.209Z
Link: CVE-2025-71319
No data.
Status : Received
Published: 2026-06-09T21:17:03.153
Modified: 2026-06-09T21:17:03.153
Link: CVE-2025-71319
No data.
OpenCVE Enrichment
Updated: 2026-06-09T22:15:15Z
Weaknesses
Github GHSA