Vulnerability GHSA-5p2g-fcmc-qvqq
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 10, 2026 at 03:31 PM UTC
image-size: JXL and HEIF parsers allow denial of service through infinite loops
1.2.0 - 2.0.2
1.2.0 - 2.0.2
Summary
image-size: JXL and HEIF parsers allow denial of service through infinite loops
Details
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 months ago
image-size: ICNS parser allows denial of service through an infinite loop
0.6.3 - 2.0.2 GHSA-w3rx-r6r6-pgpr
0.6.3 - 2.0.2 GHSA-w3rx-r6r6-pgpr
High Risk
1 year ago
image-size Denial of Service via Infinite Loop during Image Processing
1.1.0 - 1.2.0 and 2.0.0 - 2.0.1 GHSA-m5qc-5hw7-8vg7
1.1.0 - 1.2.0 and 2.0.0 - 2.0.1 GHSA-m5qc-5hw7-8vg7
Impacted packages
Timeline
Published
3 months ago
June 10, 2026 at 03:31 PM UTC
Fixed (2.0.3)
Unknown
Unknown
Last Modified
4 days ago
September 24, 2026 at 06:45 PM UTC