DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-104861: CVE-2026-104861: Quadratic-time Regular Expression Denial of Service in probe-image-size SVG Parser

CVE-2026-104861: Quadratic-time Regular Expression Denial of Service in probe-image-size SVG Parser

Vulnerability ID: CVE-2026-104861
CVSS Score: 7.5
Published: 2026-10-02

An uncontrolled resource consumption vulnerability (CWE-1333 / CWE-400) exists in probe-image-size versions prior to 7.4.0. The SVG parser utilizes an unanchored, inefficient regular expression to find the SVG root tag, leading to catastrophic backtracking when handling malformed payloads. This blocks the single-threaded Node.js event loop, resulting in a complete denial of service.

TL;DR

Unauthenticated remote attackers can cause complete CPU exhaustion and Denial of Service in Node.js applications using probe-image-size by supplying malformed SVG streams with unclosed opening brackets.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-1333, CWE-400
  • Attack Vector: Network (AV:N)
  • CVSS Severity Score: 7.5 (High)
  • EPSS Score: 0.00043
  • Impact: Denial of Service (DoS)
  • Exploit Status: Proof of Concept Available
  • KEV Status: Not Listed

Affected Systems

  • probe-image-size (npm package)
  • probe-image-size: < 7.4.0 (Fixed in: 7.4.0)

Code Analysis

Commit: 60cc96a

Parse the XML prolog and the root element of an SVG document securely with anchored regex patterns.

Commit: c032aef

Lower the MAX_DATA_LENGTH boundary limit for SVG processing from 64 KB to 10 KB.

Commit: 9b74656

Restrict the whitespace matching regex logic to prevent infinite backtracking over leading whitespaces.

Exploit Details

  • GitHub Security Advisory: Proof of concepts illustrating synchronous parser event loop blocking and streaming chunk amplification exploitation.

Mitigation Strategies

  • Upgrade probe-image-size to version 7.4.0 or later.
  • Deploy WAF rules to reject XML/SVG requests larger than 10 KB.
  • Implement request timeouts on image download endpoints to prevent streaming connection hanging.

Remediation Steps:

  1. Identify applications utilizing the probe-image-size package.
  2. Update package.json dependencies to specify version ^7.4.0.
  3. Run npm update probe-image-size or yarn upgrade probe-image-size to apply the patch.
  4. Deploy the updated application to production and monitor CPU usage patterns.

References


Read the full report for CVE-2026-104861 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)