VDB
CVE-2025-71319
CVE-2025-71319
PUBLISHED
CVSS 8.7 HIGH
Reported by VulnCheck · Published June 9, 2026
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
Risk Scores
CVSS 4.0
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| image-size | image-size | 1.1.0, 2.0.0 |
| Red Hat | Red Hat Trusted Artifact Signer 1.4 | 1783327185 |
| Red Hat | Gatekeeper 3 | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat Build of Podman Desktop | |
| Red Hat | Red Hat Trusted Artifact Signer 1.4 | |
| Red Hat | Red Hat Build of Podman Desktop | |
| Red Hat | Red Hat Fuse 7 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat OpenShift Dev Spaces | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | |
| Red Hat | Red Hat OpenShift Dev Spaces | |
| Red Hat | Red Hat Satellite 6 | |
| Red Hat | Red Hat Trusted Artifact Signer | |
| Red Hat | Red Hat Enterprise Linux 8 |
…and 11 more
Timeline
- Apr 2, 2025 CVE Published
- Jun 11, 2026 Coalition ESS Score
- Jun 11, 2026 Security Advisory
- Jul 1, 2026 Distribution Patch
- Jul 1, 2026 Security Advisory
- Jul 10, 2026 Distribution Patch
- Jul 11, 2026 Security Advisory
References
- technical-descriptionexploit
- issue-tracking
- third-party-advisory
- GitHub Security Advisory (GHSA-m5qc-5hw7-8vg7) vendor-advisory
- https://www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-findbox-function third-party-advisory
- https://access.redhat.com/security/cve/CVE-2025-71319 vdb
- RHBZ#2487296 issue
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-71319.json url
- https://access.redhat.com/errata/RHSA-2026:33313 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:37272 vendor-advisory