Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whj4-6x5x-4v2j

Опубликовано: 13 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

FITS GZIP decompression bomb in Pillow

Impact

Pillow did not limit the amount of GZIP-compressed data read when decoding a FITS image, making it vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation).

Patches

The amount of data read is now limited to the necessary amount. Fixed in Pillow 12.2.0 (PR #9521).

Workarounds

Avoid Pillow >= 10.3.0, < 12.2.0 Only open specific image formats, excluding FITS.

Пакеты

Наименование

pillow

pip
Затронутые версииВерсия исправления

>= 10.3.0, < 12.2.0

12.2.0

EPSS

Процентиль: 48%
0.00671
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
redhat
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
nvd
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
debian
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did ...

suse-cvrf
3 месяца назад

Security update for python-Pillow

EPSS

Процентиль: 48%
0.00671
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770