Vulnerability GHSA-5p2g-fcmc-qvqq

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 10, 2026 at 03:31 PM UTC
image-size: JXL and HEIF parsers allow denial of service through infinite loops
1.2.0 - 2.0.2
1.2.0 - 2.0.2

Summary

image-size: JXL and HEIF parsers allow denial of service through infinite loops

Details

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.

Impacted packages

Timeline

Published
3 months ago
June 10, 2026 at 03:31 PM UTC
Fixed (2.0.3)
Unknown
Unknown
Last Modified
4 days ago
September 24, 2026 at 06:45 PM UTC