LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2025-71330

image-size · image-size

Published
CVSS7.5
Severityhigh
WeaknessCWE-835
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length field is 0, causing the while loop condition to remain true indefinitely.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-71330

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-71330.