Quadratic-time Denial of Service in probe-image-size SVG Parser
The probe-image-size package is vulnerable to a denial-of-service attack due to a regular expression exhibiting quadratic time complexity when processing maliciously crafted SVG payloads.
CVE search metadata
CVE search record: CVE-2026-104861. Severity: high. CVSS: 7.5. KEV: no. Product: probe-image-size (<= 7.3.0). Brief: Quadratic-time Denial of Service in probe-image-size SVG Parser. Brief link: https://feed.craftedsignal.io/briefs/2026-10-probe-image-size-dos/
The probe-image-size package (v7.3.0 and earlier) is vulnerable to a Denial of Service (DoS) attack caused by an inefficient regular expression used to scan SVG headers. The regex /<[-_.:a-zA-Z0-9][^>]*>/ triggers quadratic time complexity when it processes an input buffer containing a high density of < characters without corresponding > closing tags. Because the parser restarts the scan at every < position and traverses to the end of the input, a relatively small payload can force the Node.js process to consume 100% CPU.
This vulnerability impacts the synchronous (probe.sync()) and streaming (probe(stream), probe(url)) parsing paths. In production environments such as link unfurlers or image processing proxies, the CPU exhaustion causes the Node.js event loop to block, rendering the service unresponsive. Attackers can exploit this by submitting a simple URL pointing to a crafted malicious SVG.
Impact
Successful exploitation leads to complete service unavailability of the affected application. Because the vulnerability affects image upload validators and link preview services, the impact is severe for web-facing applications. A minimal number of concurrent requests is sufficient to crash or hang a Node.js process, and the ability to trigger this remotely via URL makes it highly accessible for exploitation.
Recommendation
Prioritize the immediate upgrade of the probe-image-size package to a version beyond 7.3.0. For applications where immediate patching is not possible, implement strict validation on input size and content before passing data to the probe-image-size library. Additionally, deploy rate-limiting on endpoints that accept remote URLs for image processing to mitigate the impact of CPU-exhaustion attacks.
Immediate actions
Upgrade probe-image-size to a version later than 7.3.0
Mitigations
Implement strict file size limits and rate limiting on image processing endpoints
CVE-2026-104861