Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42310

Опубликовано: 09 мая 2026
Источник: debian

Описание

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pillowfixed12.2.0-1package
pillowpostponedbookwormpackage
pillowpostponedbullseyepackage

Примечания

  • https://github.com/python-pillow/Pillow/security/advisories/GHSA-r73j-pqj5-w3x7

  • https://github.com/python-pillow/Pillow/pull/9519

  • Fixed by: https://github.com/python-pillow/Pillow/commit/3bf614e4b8615d0ce1d5039efaf6db447fe7c468 (12.2.0)

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.

CVSS3: 4
redhat
3 месяца назад

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.

CVSS3: 5.5
nvd
3 месяца назад

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.

suse-cvrf
3 месяца назад

Security update for python-Pillow

CVSS3: 4
redos
20 дней назад

Уязвимость python-pillow