A high-severity vulnerability, assigned a CVSS score of 7.5, affects probe-image-size versions <= 7.3.0. The flaw type is a Denial of Service (DoS) in the SVG Parser, which can be exploited by an attacker to cause quadratic-time DoS attacks. This issue arises due to the absence of input size cap in the sync path and repeated rescanning in the stream path, allowing an attacker to supply a link that blocks the Node.js event loop at 100% CPU for the whole duration. The business impact is significant, as this vulnerability can be used to deny service in production environments such as upload validators, image proxies or link unfurl services. An affected entry point reaches the SVG parser: probe.sync, probe(stream), and probe(url).
We recommend you to update probe-image-size to version 7.4.0.[/subscribe_to_unlock_form]
A high-severity vulnerability, assigned a CVSS score of 7.5, affects probe-image-size versions <= 7.3.0. The flaw type is a Denial of Service (DoS) in the SVG Parser, which can be exploited by an attacker to cause quadratic-time DoS attacks. This issue arises due to the absence of input size cap in the sync path and repeated rescanning in the stream path, allowing an attacker to supply a link that blocks the Node.js event loop at 100% CPU for the whole duration. The business impact is significant, as this vulnerability can be used to deny service in production environments such as upload validators, image proxies or link unfurl services. An affected entry point reaches the SVG parser: probe.sync, probe(stream), and probe(url).
We recommend you to update probe-image-size to version 7.4.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]