{"id":"CVE-2025-71329","summary":"image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser","details":"image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.","aliases":["GHSA-5p2g-fcmc-qvqq"],"modified":"2026-08-12T03:51:23.969191821Z","published":"2026-06-10T13:04:30.380Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-835"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71329.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71329.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71329"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-jxl-heif-parser"},{"type":"REPORT","url":"https://web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439"},{"type":"PACKAGE","url":"https://github.com/image-size/image-size"},{"type":"EVIDENCE","url":"https://joshua.hu/image-size-infinite-loop-dos-vulnerabilities"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/image-size/image-size","events":[{"introduced":"0c822974cee05ccf26f8ee9c4612797e2d6bb77c"},{"last_affected":"a4178fbb334ddb22d94cb4228ed597c24fd02e10"},{"introduced":"1fb8f411593acbdb413eaf97817a8eb0b7e8af83"},{"last_affected":"032c3347b86f09a2e16449e17537cf5e1009520c"}],"database_specific":{"cpe":"cpe:2.3:a:image-size:image-size:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.1.0"},{"last_affected":"1.2.1"},{"introduced":"2.0.0"},{"last_affected":"2.0.2"}],"source":"CPE_RANGE"}}],"versions":["v2.0.2","v1.2.1","v1.2.0","v2.0.1","v2.0.0","v1.1.1","v1.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71329.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}