Advisories for Npm/Probe-Image-Size package

2026

probe-image-size: Quadratic-time Denial of Service in the SVG Parser

Every entry point that reaches the SVG parser is affected: probe.sync(), probe(stream) and probe(url). The URL form is the most exposed one — the input is fetched from a remote host, so an attacker only needs to supply a link. Processing a crafted buffer blocks the Node.js event loop at 100% CPU for the whole duration. In production environments such as upload validators, image proxies or link unfurl services, a …