CVE-2024-21523

HIGH

NPM Images - Denial of Service

Title source: rule
STIX 2.1

Description

All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values (like 0) to the size function, it is possible to obtain a Segmentation fault error, leading to the process crash.

Scores

CVSS v3 7.5
EPSS 0.0022
EPSS Percentile 44.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-241 CWE-400
Status published
Products (2)
n/a/images
npm/images 0npm
Published Jul 10, 2024
Tracked Since Feb 18, 2026