You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Highly-compressed images in the form of large PNGs or malicious PNG decompression bombs could lead to OutOfMemoryErrors.
While I haven't researched whether decompression bombs can actually happen with the default PNG reader bundled with Java, if such things can happen, then a countermeasure against them would be nice to incorporate in Thumbnailator.
coobird
changed the title
Protection from malicious or highly-compressed images
Protection against denial-of-service from malicious or highly-compressed images
Apr 29, 2022
Highly-compressed images in the form of large PNGs or malicious PNG decompression bombs could lead to
OutOfMemoryError
s.While I haven't researched whether decompression bombs can actually happen with the default PNG reader bundled with Java, if such things can happen, then a countermeasure against them would be nice to incorporate in Thumbnailator.
References:
The text was updated successfully, but these errors were encountered: