ZERO
Back
vulnerabilityCVE-2026-104861

CVE-2026-104861

A flaw was found in probe-image-size. An unauthenticated remote attacker can exploit this vulnerability to cause a Denial of Service (DoS) by supplying specially crafted Scalable Vector Graphics (SVG) input. Due to inefficient pattern matching and input handling during SVG parsing, processing unclosed tags can consume excessive CPU resources and block the application event loop, leaving the service unresponsive.

Exploitation evidence
None confirmed

Affected software

CVSS (Common Vulnerability Scoring System)

Preferred assessment

Vector

Attack vector

Attack complexity

Privileges required

User interaction

Scope

Confidentiality impact

Integrity impact

Availability impact

Source assessments

EPSS (Exploit Prediction Scoring System)

Probability

Percentile

Model

Preferred remediation

Action