All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash.
**Note:**
By providing some specific integer values (like 0) to the size function, it is possible to obtain a Segmentation fault error, leading to the process crash.
**Note:**
By providing some specific integer values (like 0) to the size function, it is possible to obtain a Segmentation fault error, leading to the process crash.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2424 | All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values (like 0) to the size function, it is possible to obtain a Segmentation fault error, leading to the process crash. |
Github GHSA |
GHSA-vjpv-x8p9-7p85 | images vulnerable to Denial of Service |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 26 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Npmjs
Npmjs images |
|
| CPEs | cpe:2.3:a:npmjs:images:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Npmjs
Npmjs images |
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-06-26T15:25:05.686Z
Reserved: 2023-12-22T12:33:20.121Z
Link: CVE-2024-21523
Updated: 2024-08-01T22:27:34.807Z
Status : Deferred
Published: 2024-07-10T05:15:11.153
Modified: 2026-06-17T07:09:40.427
Link: CVE-2024-21523
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA