HIGH · 7.5

CVE-2025-71319

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-v...

Vulnerability Description

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Image-SizeImage-Size>= 1.1.0, <= 1.2.1
RedhatDiscovery2.0
RedhatGatekeeper3.0
RedhatTrusted Artifact Signer>= 1.4, < 1.4.2
RedhatEnterprise Linux8.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-71319?

CVE-2025-71319 is a vulnerability with a CVSS score of 7.5 (HIGH). image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-v...

How severe is CVE-2025-71319?

CVE-2025-71319 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-71319?

Check the references section above for vendor advisories and patch information. Affected products include: Image-Size Image-Size, Redhat Discovery, Redhat Gatekeeper, Redhat Trusted Artifact Signer, Redhat Enterprise Linux.