HIGH🇵🇱 Wersja polska

CVE-2026-40192

CVSS 8.7v4.0pub. 2026-04-15upd. 2026-09-01

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Python Pillow

    APP
    Python
    10.3.0 – 12.2.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2022-30595CRITICAL9.8PL ✓same product

Heap buffer overflow w Pillow 9.1.0 przy przetwarzaniu plików TGA

CVE-2022-24303CRITICAL9.1PL ✓same product

Pillow: nieprawidłowa obsługa spacji w ścieżkach tymczasowych umożliwia usuwanie plików

CVE-2022-22817CRITICAL9.8PL ✓same product

Pillow: wykonanie dowolnego kodu przez PIL.ImageMath.eval przed wersją 9.0.0

CVE-2021-34552CRITICAL9.8PL ✓same product

Buffer overflow w Pillow/PIL przez niekontrolowane parametry Convert.c

CVE-2021-25287CRITICAL9.1PL ✓same product

Out-of-bounds read w Pillow — błąd dekodowania JPEG 2000 (J2kDecode)