Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 Node.js & npm GHSA-gjj5-9665-rwrc CVE-2026-104861

probe-image-size: ReDoS-style SVG Parsing Flaw Enables CPU-based Denial of Service

A flaw in probe-image-size's SVG parsing regular expression allows attacker-controlled input to trigger excessive CPU consumption, potentially blocking the Node.js event loop. Fixed in version 7.4.0.

Synthesized by AI from 2 sources · updated 2 hours ago

AI summary

A vulnerability has been disclosed in probe-image-size, a Node.js library used to determine image dimensions without downloading full files. The issue, tracked as CVE-2026-104861, affects how the library parses SVG input and can be exploited to cause excessive CPU usage. A fixed version is available.

What happened

probe-image-size's SVG parsing code, found in lib/parse_sync/svg.js and lib/parse_stream/svg.js, uses a regular expression (/<[-_.:a-zA-Z0-9][^>]*>/) to scan SVG markup. When the input contains many '<' characters without a matching closing '>', this regular expression repeatedly scans to the end of the input, resulting in disproportionately high processing time relative to input size.

Technical cause

The synchronous parser (probe.sync()) converts and scans the entire supplied buffer without any cap on input size. The streaming parser, used by probe(stream) and probe(url), is affected differently but similarly: it reparses the full accumulated SVG prefix on every received chunk, meaning that an attacker who controls how data is chunked can further amplify processing cost. Both code paths can drive CPU usage to 100% and block the Node.js event loop while the vulnerable code runs. This is classified as CWE-400 (Uncontrolled Resource Consumption).

Why it matters

Because probe.sync(), probe(stream), and probe(url) are all affected, any application that processes SVG input from an untrusted source through probe-image-size is exposed. A single malicious SVG payload can stall event loop processing for the entire Node.js process, affecting all requests being served, not just the one containing the malicious input.

Who is affected

Any application or service using probe-image-size to inspect SVG files from sources that are not fully trusted (e.g., user uploads, remote URLs) is potentially affected. The vulnerability applies to both the synchronous and streaming parsing entry points.

Affected versions

All versions of probe-image-size from the initial release up to and including 7.3.0 are affected. Version 7.4.0 contains the fix.

Fixes and mitigation

The vendor has released version 7.4.0, which resolves this issue. Users should upgrade from any version up to and including 7.3.0 to 7.4.0.

Recommended action

Upgrade probe-image-size to version 7.4.0 as soon as possible, particularly in applications that process SVG files originating from untrusted or external sources. Until the upgrade is applied, consider limiting or sanitizing SVG input sizes and sources as a temporary mitigation.

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Why this score

This vulnerability has a CVSS base score of 7.5 (High), reflecting a network-exploitable Denial of Service condition that requires no authentication and no user interaction, with high impact on availability and no impact on confidentiality or integrity. The PatchBriefing score of 4.9 accounts for this CVSS base score along with the facts that the vulnerability is remotely exploitable without authentication and requires no user interaction, slightly raising the score. No known exploitation in the wild, no public exploit code, and no elevated EPSS probability were found, which keeps the overall score moderate rather than critical. A fix is available, which also limits ongoing risk once applied.

Affected versions

probe-image-size <= 7.3.0
vulnerable
≥ 7.4.0
patched

Reported fixes

The vendor has released version 7.4.0, which resolves this issue. Users should upgrade from any version up to and including 7.3.0 to 7.4.0.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
probe-image-size: ReDoS-style SVG Parsing Flaw Enables CPU-based Denial of Service
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email