Remote Crash Vulnerability in ImageCLI Affects Applications Using the Library
CVE-2026-70377

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-70377?

The vulnerability arises from the scale <ratio> pipeline operation in ImageCLI, where input ratios from the command line are not validated for upper limits. Consequently, supplying an excessively large ratio can lead to attempts to allocate impractical memory sizes, causing the program to terminate unexpectedly. This flaw puts any application that integrates ImageCLI and processes user-defined pipeline strings at risk of remote crash, enabling an attacker to disrupt service with a single crafted request.

Affected Version(s)

imagecli 0 <= 0.2.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

agrresore
.