Articles in this topic
A 4 KB PNG can decode to 12 GB. Read dimensions from the header with Sharp metadata(), enforce a pixel budget, then decode behind limitInputPixels.
Read article →Detect spoofed uploads by reading magic bytes with libmagic in Node.js — a bounded-memory stream gate, a flag reference, and native-binding fixes.
Read article →Accept user SVGs without script injection — allow-list elements with DOMPurify, strip external references, serve under a sandboxing CSP, or rasterise.
Read article →Check PDF uploads server-side — verify the header, parse with qpdf in a sandbox, flag JavaScript and embedded files, cap page counts, and re-render risky ones.
Read article →Use ffprobe JSON to accept only decodable video — check container, codecs, duration, resolution and frame rate, then decode a sample to catch corrupt files.
Read article →