<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:probe-Image-Size_project:probe-Image-Size:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aprobe-image-size_projectprobe-image-size/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 04:50:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aprobe-image-size_projectprobe-image-size/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Quadratic-time Denial of Service in probe-image-size SVG Parser</title><link>https://feed.craftedsignal.io/briefs/2026-10-probe-image-size-dos/</link><pubDate>Sat, 03 Oct 2026 04:50:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-probe-image-size-dos/</guid><description>The probe-image-size package is vulnerable to a denial-of-service attack due to a regular expression exhibiting quadratic time complexity when processing maliciously crafted SVG payloads.</description><content:encoded><![CDATA[<p>The probe-image-size package (v7.3.0 and earlier) is vulnerable to a Denial of Service (DoS) attack caused by an inefficient regular expression used to scan SVG headers. The regex <code>/&lt;[-_.:a-zA-Z0-9][^&gt;]*&gt;/</code> triggers quadratic time complexity when it processes an input buffer containing a high density of <code>&lt;</code> characters without corresponding <code>&gt;</code> closing tags. Because the parser restarts the scan at every <code>&lt;</code> position and traverses to the end of the input, a relatively small payload can force the Node.js process to consume 100% CPU.</p>
<p>This vulnerability impacts the synchronous (<code>probe.sync()</code>) and streaming (<code>probe(stream)</code>, <code>probe(url)</code>) parsing paths. In production environments such as link unfurlers or image processing proxies, the CPU exhaustion causes the Node.js event loop to block, rendering the service unresponsive. Attackers can exploit this by submitting a simple URL pointing to a crafted malicious SVG.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to complete service unavailability of the affected application. Because the vulnerability affects image upload validators and link preview services, the impact is severe for web-facing applications. A minimal number of concurrent requests is sufficient to crash or hang a Node.js process, and the ability to trigger this remotely via URL makes it highly accessible for exploitation.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate upgrade of the <code>probe-image-size</code> package to a version beyond 7.3.0. For applications where immediate patching is not possible, implement strict validation on input size and content before passing data to the <code>probe-image-size</code> library. Additionally, deploy rate-limiting on endpoints that accept remote URLs for image processing to mitigate the impact of CPU-exhaustion attacks.</p>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>nodejs</category><category>software-vulnerability</category></item></channel></rss>