{"record":{"id":"ffb05183dd277a1a","repo":"paperclipai/paperclip","slug":"invalid-heif-image-dimensions","errorCode":null,"errorMessage":"Invalid HEIF image dimensions","messagePattern":"Invalid HEIF image dimensions","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"server/src/services/photon/media.ts","lineNumber":46,"sourceCode":"      let header = 8;\n      if (size === 1) {\n        if (end - at < 16) throw new Error(\"Invalid HEIF box length\");\n        const extended = body.readBigUInt64BE(at + 8);\n        if (extended > BigInt(body.length))\n          throw new Error(\"HEIF box exceeds file bounds\");\n        size = Number(extended);\n        header = 16;\n      } else if (size === 0) size = end - at;\n      if (size < header || at + size > end)\n        throw new Error(\"HEIF box exceeds file bounds\");\n      const content = at + header;\n      if (type === \"ftyp\") {\n        if (size < header + 8) throw new Error(\"HEIF file type is missing\");\n        const brands = body.toString(\"ascii\", content, at + size);\n        branded = /heic|heix|hevc|hevx|mif1|msf1/.test(brands);\n      } else if (type === \"ispe\") {\n        if (size !== header + 12)\n          throw new Error(\"Invalid HEIF image dimensions\");\n        const width = body.readUInt32BE(content + 4);\n        const height = body.readUInt32BE(content + 8);\n        if (\n          !width ||\n          !height ||\n          width > 16_384 ||\n          height > 16_384 ||\n          width * height > MAX_PIXELS\n        )\n          throw new Error(\"HEIF decoded image exceeds the pixel limit\");\n        totalPixels += width * height;\n        if (totalPixels > MAX_PIXELS * 3 || ++dimensions > 512)\n          throw new Error(\"HEIF image collection exceeds the pixel limit\");\n      } else if ([\"meta\", \"iprp\", \"ipco\"].includes(type)) {\n        visit(content + (type === \"meta\" ? 4 : 0), at + size, depth + 1);\n      }\n      at += size;\n    }","sourceCodeStart":28,"sourceCodeEnd":64,"githubUrl":"https://github.com/paperclipai/paperclip/blob/3f1d897a7c018d76563a21c6e39c3c9b03933622/server/src/services/photon/media.ts#L28-L64","documentation":"An ispe (image spatial extent) box must be exactly header + 12 bytes (version/flags 4 + width 4 + height 4). Any other size throws \"Invalid HEIF image dimensions\". This precedes reading width/height so the parser never reads dimensions from a malformed box.","triggerScenarios":"An ispe box whose total size is not exactly 20 bytes (8-byte header + 12 content) encountered while walking the iprp/ipco property containers (media.ts:44-46).","commonSituations":"Corrupted or deliberately malformed HEIC with oversized/undersized ispe; files produced by nonconformant encoders; fuzzed inputs probing dimension parsing.","solutions":["Reject the file and re-export a clean HEIC/HEIC from the origin application.","Validate locally with `heif-info`/`ffprobe` — a nonconformant ispe means a broken encoder was used.","Re-encode with a mainstream tool (sips, ImageMagick with HEIF support, libheif's heif-enc).","If the file is hostile input, keep it blocked; the exact-size check is intentional."],"exampleFix":"// before: malformed ispe (size 24)\n// after: re-encode with libheif\nheif-enc input.jpg -o output.heic","handlingStrategy":"validation","validationCode":"function ispeSizeValid(buf: Buffer, at: number): boolean {\n  const size = buf.readUInt32BE(at);\n  const header = size === 1 ? 16 : 8;\n  return size === header + 12;\n}","typeGuard":"function isWellFormedIspe(b: Buffer, boxStart: number): boolean {\n  return b.readUInt32BE(boxStart) === 20;\n}","tryCatchPattern":"try {\n  validateHeifDimensions(body);\n} catch (e) {\n  if (e instanceof Error && e.message === \"Invalid HEIF image dimensions\") {\n    return rejectUpload(\"HEIF spatial-extent box is malformed; re-encode the image\");\n  }\n  throw e;\n}","preventionTips":["Encode HEIFs only with conformant encoders (libheif, Apple tooling).","Validate with heif-info/ffprobe before upload in pipelines.","Reject files whose ispe boxes deviate from the ISO-specified 12-byte payload.","Keep the strict size equality; permissiveness here exposes dimension parsing to malformed data."],"tags":["heif","isobmff","malformed-file","input-validation"],"backgroundTag":"invalid-argument-format","analyzedSha":"3f1d897a7c018d76563a21c6e39c3c9b03933622","analyzedAt":"2026-09-18T08:03:59.046Z","contentChangedAt":"2026-09-18T08:03:59.046Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}