Security: vulnerable dependency image-size (CVE-2025-71329/71330) — maintained drop-in available
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 58/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- javascript, react-native
- Domain
- mobile-dev, security
Research direction
Start with package.json and the shown imageSize import, checking whether image-size is direct or transitive and whether the proposed override applies. Done means the vulnerable dependency is no longer resolved and the maintained package preserves the existing public API.
Written by the indexing model from the issue text.
Description
Context
This package depends on npm image-size. Upstream is archived and the latest release (2.0.2) remains affected by:
- CVE-2025-71329 — DoS via infinite loop (JXL/HEIF/JP2 zero-size boxes)
- CVE-2025-71330 — DoS via infinite loop (ICNS zero entry length)
npm audit fix will not switch package names automatically.
Maintained drop-in
Community MIT fork with the same public API as image-size@2.0.2:
- npm: https://www.npmjs.com/package/image-size-next (
image-size-next@2.1.0) - GitHub: https://github.com/lcf2212dev/image-size-next
- Announcement: https://github.com/lcf2212dev/image-size-next/blob/main/ANNOUNCE.md
Not affiliated with the original image-size maintainer — honest community fork only.
Migration options
A — Direct dependency
npm install image-size-next
- import { imageSize } from 'image-size'
+ import { imageSize } from 'image-size-next'
B — Force transitive resolution (npm 8.3+)
{
"overrides": {
"image-size": "npm:image-size-next@2.1.0"
}
}
Ask
Happy to open a PR for @kohout.jakub/react-native if useful. Thanks for maintaining open source.
- Dominant language
- C++
- Stars
- 127k
- Forks
- 25.3k
- PR merge metrics
- No merged PRs in 30d
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from react/react-native
-
Needs: Author Feedback Needs: Repro
Difficulty 1/5 Under an hour Newbie friendliness 92/100
react/react-native#58621 · 1 comment ·
-
Needs: Author Feedback Needs: Repro
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
react/react-native#58610 · 1 comment ·
-
Needs: Triage :mag:
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
react/react-native#58565 · 1 comment · 2 reactions ·
-
Needs: Author Feedback Needs: Repro
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
react/react-native#58555 · 5 comments · 2 reactions ·
-
Needs: Attention Needs: Repro
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
react/react-native#58526 · 2 comments ·
All issues in react/react-native
Similar issues
-
ai_reviewed
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
ydb-platform/ydb#53869 · 3 comments ·
-
bug cert blocker needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
project-chip/connectedhomeip#74373 ·
-
upstream update
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
conan-io/conan-center-index#31035 ·
-
Bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
documentation
Difficulty 1/5 Under an hour Newbie friendliness 85/100
vllm-project/vllm-ascend#17329 ·