Security Advisory

CVE-2026-70377

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-05 06:58:47
Last updated 2026-08-05 13:14:14
Assigner TuranSec
CVSS score not scored
State PUBLISHED

Description

imagecli's `scale <ratio>` pipeline operation (Scale::apply() in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. A large ratio (e.g. 100000) causes an attempted allocation of hundreds of terabytes, aborting the process. Any application embedding imagecli as a library and accepting user-controlled pipeline strings is remotely crashable with a single request.