{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aprobe-image-size_projectprobe-image-size/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:probe-image-size_project:probe-image-size:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-104861"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["probe-image-size (\u003c= 7.3.0)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","nodejs","software-vulnerability"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe probe-image-size package (v7.3.0 and earlier) is vulnerable to a Denial of Service (DoS) attack caused by an inefficient regular expression used to scan SVG headers. The regex \u003ccode\u003e/\u0026lt;[-_.:a-zA-Z0-9][^\u0026gt;]*\u0026gt;/\u003c/code\u003e triggers quadratic time complexity when it processes an input buffer containing a high density of \u003ccode\u003e\u0026lt;\u003c/code\u003e characters without corresponding \u003ccode\u003e\u0026gt;\u003c/code\u003e closing tags. Because the parser restarts the scan at every \u003ccode\u003e\u0026lt;\u003c/code\u003e position and traverses to the end of the input, a relatively small payload can force the Node.js process to consume 100% CPU.\u003c/p\u003e\n\u003cp\u003eThis vulnerability impacts the synchronous (\u003ccode\u003eprobe.sync()\u003c/code\u003e) and streaming (\u003ccode\u003eprobe(stream)\u003c/code\u003e, \u003ccode\u003eprobe(url)\u003c/code\u003e) parsing paths. In production environments such as link unfurlers or image processing proxies, the CPU exhaustion causes the Node.js event loop to block, rendering the service unresponsive. Attackers can exploit this by submitting a simple URL pointing to a crafted malicious SVG.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to complete service unavailability of the affected application. Because the vulnerability affects image upload validators and link preview services, the impact is severe for web-facing applications. A minimal number of concurrent requests is sufficient to crash or hang a Node.js process, and the ability to trigger this remotely via URL makes it highly accessible for exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate upgrade of the \u003ccode\u003eprobe-image-size\u003c/code\u003e package to a version beyond 7.3.0. For applications where immediate patching is not possible, implement strict validation on input size and content before passing data to the \u003ccode\u003eprobe-image-size\u003c/code\u003e library. Additionally, deploy rate-limiting on endpoints that accept remote URLs for image processing to mitigate the impact of CPU-exhaustion attacks.\u003c/p\u003e\n","date_modified":"2026-10-03T04:50:24Z","date_published":"2026-10-03T04:50:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-probe-image-size-dos/","summary":"The probe-image-size package is vulnerable to a denial-of-service attack due to a regular expression exhibiting quadratic time complexity when processing maliciously crafted SVG payloads.","title":"Quadratic-time Denial of Service in probe-image-size SVG Parser","url":"https://feed.craftedsignal.io/briefs/2026-10-probe-image-size-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:probe-Image-Size_project:probe-Image-Size:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}