CVE-2025-71319

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:image-size:image-size:*:*:*:*:*:node.js:*:*
cpe:2.3:a:image-size:image-size:*:*:*:*:*:node.js:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:discovery:2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:gatekeeper:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:trusted_artifact_signer:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-09 21:17

Updated : 2026-07-24 20:19


NVD link : CVE-2025-71319

Mitre link : CVE-2025-71319

CVE.ORG link : CVE-2025-71319


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • discovery
  • gatekeeper
  • trusted_artifact_signer

image-size

  • image-size
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')