---
id: CVE-2026-104861
title: probe-image-size gets image dimensions without downloading the entire file
summary: >-
  probe-image-size gets image dimensions without downloading the entire file.
  Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the
  searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans
  to the en…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-1333
vendor: nodeca
product: probe-image-size
affected:
  - probe-image-size < 7.4.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:17:02.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104861'
references:
  - url: >-
      https://github.com/nodeca/probe-image-size/commit/60cc96ac0b671e79e328213d0a8e831312b09e84
    label: security-advisories@github.com
  - url: >-
      https://github.com/nodeca/probe-image-size/commit/9b74656d6f973cc59ea2ab1375c0d88390a402ad
    label: security-advisories@github.com
  - url: >-
      https://github.com/nodeca/probe-image-size/commit/c032aefabdecf5cb50548ab9ba175db56353078f
    label: security-advisories@github.com
  - url: 'https://github.com/nodeca/probe-image-size/releases/tag/7.4.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/nodeca/probe-image-size/security/advisories/GHSA-gjj5-9665-rwrc
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T18:25:05.831Z'
---

## Overview

probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans to the end of input when attacker-controlled data contains many less-than characters without a closing greater-than character. The synchronous parser converts and scans the full supplied buffer without an input cap, while the streaming parser reparses the complete accumulated SVG prefix for every received chunk. The probe.sync(), probe(stream), and probe(url) entry points can therefore block the Node.js event loop at full CPU, and attacker-controlled chunking can amplify the streaming cost. This issue is fixed in version 7.4.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
