Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40192

Опубликовано: 15 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

A flaw was found in Pillow, a Python imaging library. This vulnerability allows a remote attacker to trigger a denial of service (DoS) by providing a specially crafted FITS image file. The library's failure to limit the amount of GZIP-compressed data during decoding can lead to unbounded memory consumption, causing the system to crash or experience severe performance issues.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Corelightspeed-core/rag-tool-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Will not fix
Red Hat Ansible Automation Platform 2python-pillowNot affected
Red Hat Enterprise Linux 7python-pillowOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-409
https://bugzilla.redhat.com/show_bug.cgi?id=2458856Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing

EPSS

Процентиль: 48%
0.00671
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
nvd
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
debian
4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did ...

suse-cvrf
3 месяца назад

Security update for python-Pillow

CVSS3: 7.5
github
4 месяца назад

FITS GZIP decompression bomb in Pillow

EPSS

Процентиль: 48%
0.00671
Низкий

7.5 High

CVSS3