Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-40192

4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-40192

4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-40192

4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-40192

4 месяца назад

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20617-1

3 месяца назад

Security update for python-Pillow

EPSS: Низкий
github логотип

GHSA-whj4-6x5x-4v2j

4 месяца назад

FITS GZIP decompression bomb in Pillow

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260713-73-0019

20 дней назад

Уязвимость python-pillow

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-05627

больше 2 лет назад

Уязвимость библиотеки для работы с изображениями Pillow, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-40192

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-40192

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-40192

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS3: 7.5
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-40192

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did ...

CVSS3: 7.5
1%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20617-1

Security update for python-Pillow

1%
Низкий
3 месяца назад
github логотип
GHSA-whj4-6x5x-4v2j

FITS GZIP decompression bomb in Pillow

CVSS3: 7.5
1%
Низкий
4 месяца назад
redos логотип
ROS-20260713-73-0019

Уязвимость python-pillow

CVSS3: 7.5
1%
Низкий
20 дней назад
fstec логотип
BDU:2026-05627

Уязвимость библиотеки для работы с изображениями Pillow, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.