CVE-2025-71319

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:image-size:image-size:*:*:*:*:*:node.js:*:*
cpe:2.3:a:image-size:image-size:*:*:*:*:*:node.js:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:discovery:2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gatekeeper:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:trusted_artifact_signer:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

History

24 Jul 2026, 20:19

Type Values Removed Values Added
First Time Redhat discovery
Redhat enterprise Linux
Redhat gatekeeper
Redhat
Redhat trusted Artifact Signer
CPE cpe:2.3:a:redhat:gatekeeper:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:discovery:2.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:trusted_artifact_signer:*:*:*:*:*:*:*:*
References () https://access.redhat.com/errata/RHSA-2026:33313 - () https://access.redhat.com/errata/RHSA-2026:33313 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2026:37272 - () https://access.redhat.com/errata/RHSA-2026:37272 - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2025-71319 - () https://access.redhat.com/security/cve/CVE-2025-71319 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2487296 - () https://bugzilla.redhat.com/show_bug.cgi?id=2487296 - Issue Tracking, Third Party Advisory
References () https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-71319.json - () https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-71319.json - Third Party Advisory

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) image-size 1.1.0 anterior a 1.2.1 y 2.0.0 anterior a 2.0.2 contienen una vulnerabilidad de denegación de servicio en la función findBox al procesar imágenes especialmente manipuladas con cajas de tamaño cero. Atacantes remotos pueden causar el bloqueo de la aplicación al suministrar archivos de imagen JXL, HEIF o JP2 maliciosos con tamaño de caja cero, desencadenando bucles infinitos durante la validación de la imagen.

10 Jul 2026, 12:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:37272 -

30 Jun 2026, 03:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:33313 -
  • () https://access.redhat.com/security/cve/CVE-2025-71319 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2487296 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-71319.json -

15 Jun 2026, 17:52

Type Values Removed Values Added
CPE cpe:2.3:a:image-size:image-size:*:*:*:*:*:node.js:*:*
References () https://joshua.hu/image-size-infinite-loop-dos-vulnerabilities - () https://joshua.hu/image-size-infinite-loop-dos-vulnerabilities - Exploit, Third Party Advisory
References () https://web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439 - () https://web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439 - Issue Tracking, Patch
References () https://www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-jxl-heif-parser - () https://www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-jxl-heif-parser - Third Party Advisory
First Time Image-size image-size
Image-size

10 Jun 2026, 14:16

Type Values Removed Values Added
Summary (en) image-size 1.1.0 before 1.2.1 and 2.0.0 before 2.0.2 contain a denial of service vulnerability in the findBox function when processing specially crafted images with zero-sized boxes. Remote attackers can cause application hang by supplying malicious JXL, HEIF, or JP2 image files with box size zero, triggering infinite loops during image validation. (en) image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
References
  • {'url': 'https://github.com/image-size/image-size/security/advisories/GHSA-m5qc-5hw7-8vg7', 'source': 'disclosure@vulncheck.com'}
  • {'url': 'https://www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-findbox-function', 'source': 'disclosure@vulncheck.com'}
  • () https://joshua.hu/image-size-infinite-loop-dos-vulnerabilities -
  • () https://web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439 -
  • () https://www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-jxl-heif-parser -

09 Jun 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 21:17

Updated : 2026-07-24 20:19


NVD link : CVE-2025-71319

Mitre link : CVE-2025-71319

CVE.ORG link : CVE-2025-71319


JSON object : View

Products Affected

redhat

  • trusted_artifact_signer
  • gatekeeper
  • discovery
  • enterprise_linux

image-size

  • image-size
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')