Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59200

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
Версия от 5.1.0 (включая) до 12.3.0 (исключая)

EPSS

Процентиль: 31%
0.00385
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
18 дней назад

Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.

CVSS3: 7.5
redhat
18 дней назад

Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.

CVSS3: 7.5
debian
18 дней назад

Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser ...

CVSS3: 7.5
github
12 дней назад

Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

CVSS3: 7.5
fstec
около 1 месяца назад

Уязвимость функции PdfParser.PdfStream.decode() модуля PIL/PdfParser.py библиотеки для работы с изображениями Pillow, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 31%
0.00385
Низкий

7.5 High

CVSS3

Дефекты

CWE-400