CVE-2026-70377: Theotherphil Imagecli

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embedding imagecli as a library and accepting user-controlled pipeline strings is remotely crashable with a single request.

Affected products

Published 2026-08-05. Last modified 2026-08-28.