<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 02:48:31 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-363389</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-363389</link>
      <description>EUVD-2026-363389</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-363389</guid>
    </item>
    <item>
      <title>fkie_cve-2025-71319</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-71319</link>
      <description>&lt;p&gt;image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-71319</guid>
    </item>
    <item>
      <title>GHSA-m5qc-5hw7-8vg7 — image-size Denial of Service via Infinite Loop during Image Processing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m5qc-5hw7-8vg7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: image-size&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`image-size` is vulnerable to a Denial of Service vulnerability when processing specially crafted images.&lt;/p&gt;
&lt;p&gt;The issue occurs because of an infine loop in `findBox` when processing certain images with a box with size `0`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;If the first bytes of the input does not match any bytes in `firstBytes`, then the package tries to validate the image using other handlers:
```js
// https://github.com/image-size/image-size/blob/v1.2.0/lib/detector.ts#L20-L31
export function detector(input: Uint8Array): imageType | undefined {
  const byte = input[0]
  if (byte in firstBytes) {
    const type = firstBytes[byte]
    if (type &amp;amp;&amp;amp; typeHandlers[type].validate(input)) {
      return type
    }
  }&lt;/p&gt;
&lt;p&gt;const finder = (key: imageType) =&amp;gt; typeHandlers[key].validate(input) //&amp;lt;--
  return keys.find(finder)
}
```&lt;/p&gt;
&lt;p&gt;Some handlers that call `findBox` to validate or calculate the image size are `jxl`, `heif` and `jp2`.&lt;/p&gt;
&lt;p&gt;`JXL` handler calls `findBox` inside `validate`. To reach the `findBox` call, the value at position `4:8` should be `&amp;#39;JXL &amp;#39;`
```js
// https://github.com/image-size/image-size/blob/v1.2.0/lib/types/jxl.ts#L51-L60
export const JXL: IImage = {
  validate: (input: Uint8Array): boolean =&amp;gt; {
    const boxType = toUTF8String(input, 4, 8)
    if (boxType !== &amp;#39;JXL &amp;#39;) return false      //&amp;lt;---&lt;/p&gt;
&lt;p&gt;const ftypBox = findBox(input, &amp;#39;ftyp&amp;#39;, 0) //&amp;lt;---
    if (!ftypBox) return false&lt;/p&gt;
&lt;p&gt;const brand = toUTF8String(input, ftypBox.offset + 8, ftypBox.offset + 12)
    return brand ===…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: image-size&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`image-size` is vulnerable to a Denial of Service vulnerability when processing specially crafted images.&lt;/p&gt;
&lt;p&gt;The issue occurs because of an infine loop in `findBox` when processing certain images with a box with size `0`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;If the first bytes of the input does not match any bytes in `firstBytes`, then the package tries to validate the image using other handlers:
```js
// https://github.com/image-size/image-size/blob/v1.2.0/lib/detector.ts#L20-L31
export function detector(input: Uint8Array): imageType | undefined {
  const byte = input[0]
  if (byte in firstBytes) {
    const type = firstBytes[byte]
    if (type &amp;amp;&amp;amp; typeHandlers[type].validate(input)) {
      return type
    }
  }&lt;/p&gt;
&lt;p&gt;const finder = (key: imageType) =&amp;gt; typeHandlers[key].validate(input) //&amp;lt;--
  return keys.find(finder)
}
```&lt;/p&gt;
&lt;p&gt;Some handlers that call `findBox` to validate or calculate the image size are `jxl`, `heif` and `jp2`.&lt;/p&gt;
&lt;p&gt;`JXL` handler calls `findBox` inside `validate`. To reach the `findBox` call, the value at position `4:8` should be `&amp;#39;JXL &amp;#39;`
```js
// https://github.com/image-size/image-size/blob/v1.2.0/lib/types/jxl.ts#L51-L60
export const JXL: IImage = {
  validate: (input: Uint8Array): boolean =&amp;gt; {
    const boxType = toUTF8String(input, 4, 8)
    if (boxType !== &amp;#39;JXL &amp;#39;) return false      //&amp;lt;---&lt;/p&gt;
&lt;p&gt;const ftypBox = findBox(input, &amp;#39;ftyp&amp;#39;, 0) //&amp;lt;---
    if (!ftypBox) return false&lt;/p&gt;
&lt;p&gt;const brand = toUTF8String(input, ftypBox.offset + 8, ftypBox.offset + 12)
    return brand ===…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m5qc-5hw7-8vg7</guid>
    </item>
    <item>
      <title>RHSA-2026:33313 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:33313</link>
      <description>&lt;p&gt;libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification libxslt: use-after-free with key data stored cross-RVT libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images. python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite nginx: ngx_http_rewrite_module: code execution and denial of service openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key libpng: libpng: Arbitrary code execution due to use-after-free vulnerability libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion vim: Command injection allows arbitrary code execution via malicious tag files urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification libxslt: use-after-free with key data stored cross-RVT libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images. python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite nginx: ngx_http_rewrite_module: code execution and denial of service openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key libpng: libpng: Arbitrary code execution due to use-after-free vulnerability libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion vim: Command injection allows arbitrary code execution via malicious tag files urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:33313</guid>
    </item>
  </channel>
</rss>
