PatchSiren

image-size CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH image-size CVE published 2026-06-10

CVE-2025-71330

CVE-2025-71330 is a high-severity denial of service vulnerability in image-size through 2.0.2. Remote attackers can exploit this vulnerability by supplying a specially crafted ICNS image buffer, potentially causing a permanent block of the Node.js event loop. The vulnerability is caused by an infinite loop in the ICNS parser when it encounters an ICNS buffer with valid magic bytes and a zero-valued entry [truncated]

HIGH image-size CVE published 2026-06-10

CVE-2025-71329

CVE-2025-71329 is a high-severity denial of service vulnerability in image-size through 2.0.2. Remote attackers can exploit this vulnerability by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type, causing an infinite loop in the JXL or HEIF image parsers and permanently hanging the application. The vulnerability has a CVSS score of 8.7 and is considered HIGH severity.

HIGH image-size CVE published 2026-06-09

CVE-2025-71319

CVE-2025-71319 is a high-severity denial of service vulnerability in image-size through 2.0.2. Remote attackers can exploit this vulnerability by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type, causing an infinite loop in the JXL or HEIF image parsers and permanently blocking the Node.js event loop.