CVE-2026-104861

Published: Ott 02, 2026 Last Modified: Ott 02, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans to the end of input when attacker-controlled data contains many less-than characters without a closing greater-than character. The synchronous parser converts and scans the full supplied buffer without an input cap, while the streaming parser reparses the complete accumulated SVG prefix for every received chunk. The probe.sync(), probe(stream), and probe(url) entry points can therefore block the Node.js event loop at full CPU, and attacker-controlled chunking can amplify the streaming cost. This issue is fixed in version 7.4.0.

400

Uncontrolled Resource Consumption

Draft
Common Consequences
Security Scopes Affected:
Availability Access Control Other
Potential Impacts:
Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Resource Consumption (Other) Bypass Protection Mechanism Other
Applicable Platforms
Technologies: Not Technology-Specific, AI/ML
View CWE Details
1333

Inefficient Regular Expression Complexity

Draft
Common Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu)
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/nodeca/probe-image-size/security/advisories/GHSA-gjj5-9665-r…
https://github.com/nodeca/probe-image-size/commit/60cc96ac0b671e79e328213d0a8e8…
https://github.com/nodeca/probe-image-size/commit/9b74656d6f973cc59ea2ab1375c0d…
https://github.com/nodeca/probe-image-size/commit/c032aefabdecf5cb50548ab9ba175…
https://github.com/nodeca/probe-image-size/releases/tag/7.4.0
https://github.com/nodeca/probe-image-size/security/advisories/GHSA-gjj5-9665-r…