Количество 8
Количество 8
GHSA-jjj6-mw9f-p565
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
CVE-2026-59200
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.
CVE-2026-59200
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.
CVE-2026-59200
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.
CVE-2026-59200
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser ...
BDU:2026-09901
Уязвимость функции PdfParser.PdfStream.decode() модуля PIL/PdfParser.py библиотеки для работы с изображениями Pillow, позволяющая нарушителю вызвать отказ в обслуживании
SUSE-SU-2026:3084-1
Security update for python-Pillow
SUSE-SU-2026:3268-1
Security update for python-Pillow
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-jjj6-mw9f-p565 Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() | CVSS3: 7.5 | 0% Низкий | 12 дней назад | |
CVE-2026-59200 Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 18 дней назад | |
CVE-2026-59200 Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 18 дней назад | |
CVE-2026-59200 Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 18 дней назад | |
CVE-2026-59200 Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser ... | CVSS3: 7.5 | 0% Низкий | 18 дней назад | |
BDU:2026-09901 Уязвимость функции PdfParser.PdfStream.decode() модуля PIL/PdfParser.py библиотеки для работы с изображениями Pillow, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
SUSE-SU-2026:3084-1 Security update for python-Pillow | 16 дней назад | |||
SUSE-SU-2026:3268-1 Security update for python-Pillow | 5 дней назад |
Уязвимостей на страницу