PT-2026-48232 · Image Size · Image-Size

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2025-71319

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
image-size 1.1.0 before 1.2.1 and 2.0.0 before 2.0.2 contain a denial of service vulnerability in the findBox function when processing specially crafted images with zero-sized boxes. Remote attackers can cause application hang by supplying malicious JXL, HEIF, or JP2 image files with box size zero, triggering infinite loops during image validation.

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

CVE-2025-71319

Affected Products

Image-Size