{"id":"CVE-2025-71329","aliases":["GHSA-5p2g-fcmc-qvqq"],"url":"https://o3.security/vulnerability/CVE-2025-71329","summary":"image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser","details":"image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.","published":"2026-06-10T13:04:30.380Z","modified":"2026-08-12T03:51:23.969191821Z","cvss":null,"epss":{"score":0.0043,"percentile":0.35636,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"image-size","fixedVersion":null}],"fix":{"url":"https://web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439","label":"image-size/image-size#439"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71329.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71329"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/image-size-denial-of-service-via-infinite-loop-in-jxl-heif-parser"},{"type":"REPORT","url":"https://web.archive.org/web/20260224152152/https://github.com/image-size/image-size/pull/439"},{"type":"PACKAGE","url":"https://github.com/image-size/image-size"},{"type":"EVIDENCE","url":"https://joshua.hu/image-size-infinite-loop-dos-vulnerabilities"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:23.969191821Z"}}