CVE-2026-104861
Deferred Deferred - Pending Action

probe-image-size SVG Parsing ReDoS Vulnerability

Vulnerability report for CVE-2026-104861, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans to the end of input when attacker-controlled data contains many less-than characters without a closing greater-than character. The synchronous parser converts and scans the full supplied buffer without an input cap, while the streaming parser reparses the complete accumulated SVG prefix for every received chunk. The probe.sync(), probe(stream), and probe(url) entry points can therefore block the Node.js event loop at full CPU, and attacker-controlled chunking can amplify the streaming cost. This issue is fixed in version 7.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nodeca probe-image-size 7.4.0
nodeca probe-image-size to 7.4.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104861 is a high-severity CPU Denial of Service (DoS) vulnerability in the probe-image-size npm package affecting versions 7.3.0 and earlier. The issue occurs in the SVG parser, which uses a regular expression to scan SVG headers. When attacker-controlled data contains many '<' characters without a closing '>', the parser repeatedly restarts scanning, causing excessive CPU usage. Both synchronous and streaming parsers are affected, with the streaming parser being particularly vulnerable when input is split into small chunks.

Detection Guidance

To detect this vulnerability, monitor for high CPU usage caused by the probe-image-size package processing malicious SVG files. Check for processes using excessive CPU when handling SVG files or URLs. Use commands like 'top' or 'htop' to identify suspicious processes. Inspect network traffic for repeated requests to SVG endpoints that may trigger the DoS condition.

Impact Analysis

This vulnerability can block the Node.js event loop at 100% CPU usage, leading to reduced availability of the application. Attackers can remotely trigger this by supplying a malicious SVG file or URL, causing the system to become unresponsive. Proof-of-concept tests show processing a 200 KB payload can take 54 seconds in synchronous mode and even longer in streaming mode with multiple chunks.

Compliance Impact

This vulnerability primarily causes a Denial of Service (DoS) by consuming excessive CPU resources, which could lead to system unavailability. While it does not directly expose or leak data, prolonged unavailability could impact compliance with regulations like GDPR (availability principle) or HIPAA (access control and integrity requirements) by disrupting services handling personal or health data.

Mitigation Strategies
  • Upgrade probe-image-size to version 7.4.0 or later to apply the patch.
  • Implement input size limits for SVG parsing in your application to prevent excessive resource consumption.
  • Monitor and restrict network requests to SVG endpoints to reduce exposure to malicious payloads.
  • Use tools like 'npm audit' to check for vulnerable versions of probe-image-size in your dependencies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104861. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart