CVE-2026-104861

CVE-2026-104861 published: probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans to the end of input when atta...

View full NVD advisory → ← Back to CVE watch