Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40192

Опубликовано: 15 апр. 2026
Источник: debian
EPSS Низкий

Описание

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed12.2.0-1package
pillownot-affectedbookwormpackage
pillownot-affectedbullseyepackage

Примечания

  • https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j

  • https://github.com/python-pillow/Pillow/pull/9521

  • Introduced with: https://github.com/python-pillow/Pillow/commit/142473c7b43a72b5dba534a26cb614b5b207ada5 (10.3.0)

  • Fixed by: https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628 (12.2.0)

EPSS

Процентиль: 48%
0.00671
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
redhat
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
nvd
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

suse-cvrf
3 месяца назад

Security update for python-Pillow

CVSS3: 7.5
github
4 месяца назад

FITS GZIP decompression bomb in Pillow

EPSS

Процентиль: 48%
0.00671
Низкий