VDB

CVE-2025-71319

CVE-2025-71319 PUBLISHED CVSS 8.7 HIGH

Reported by VulnCheck · Published June 9, 2026

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.

Risk Scores

CVSS 4.0
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
image-sizeimage-size1.1.0, 2.0.0
Red HatRed Hat Trusted Artifact Signer 1.41783327185
Red HatGatekeeper 3
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat OpenShift AI (RHOAI)
Red HatRed Hat Build of Podman Desktop
Red HatRed Hat Trusted Artifact Signer 1.4
Red HatRed Hat Build of Podman Desktop
Red HatRed Hat Fuse 7
Red HatRed Hat JBoss Enterprise Application Platform 7
Red HatRed Hat JBoss Enterprise Application Platform 7
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat OpenShift Dev Spaces
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat JBoss Enterprise Application Platform 8
Red HatRed Hat OpenShift Dev Spaces
Red HatRed Hat Satellite 6
Red HatRed Hat Trusted Artifact Signer
Red HatRed Hat Enterprise Linux 8

…and 11 more

Timeline

  • Apr 2, 2025 CVE Published
  • Jun 11, 2026 Coalition ESS Score
  • Jun 11, 2026 Security Advisory
  • Jul 1, 2026 Distribution Patch
  • Jul 1, 2026 Security Advisory
  • Jul 10, 2026 Distribution Patch
  • Jul 11, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›