vulnerabilityCVE-2026-104861
CVE-2026-104861
A flaw was found in probe-image-size. An unauthenticated remote attacker can exploit this vulnerability to cause a Denial of Service (DoS) by supplying specially crafted Scalable Vector Graphics (SVG) input. Due to inefficient pattern matching and input handling during SVG parsing, processing unclosed tags can consume excessive CPU resources and block the application event loop, leaving the service unresponsive.
Exploitation evidence
None confirmed
Affected software
| Software | Affected versions | Fixed in | Sources |
|---|---|---|---|
CVSS (Common Vulnerability Scoring System)
Preferred assessment
Vector
Attack vector
Attack complexity
Privileges required
User interaction
Scope
Confidentiality impact
Integrity impact
Availability impact
Source assessments
EPSS (Exploit Prediction Scoring System)
Probability
Percentile
Model
Preferred remediation
Action