CVE-2019-13655 is a denial-of-service vulnerability affecting Imgix versions through 2019-06-19. Attackers can exploit this by crafting a small JPEG file with excessively large dimensions (e.g., 64250x64250 pixels), causing the image processing service to consume excessive memory and crash when attempting to load the entire image. This vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring user interaction (e.g., uploading the malicious image), and leading to high availability impact (denial of service). There is no confidentiality or integrity impact. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2019-06-19CPE matchmatch criteria | cpe:2.3:a:imgix:imgix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.