Количество 33
Количество 33
CVE-2026-55380
Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.
CVE-2026-55380
Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.
CVE-2026-55380
Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.p ...
CVE-2026-55379
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.
CVE-2026-55379
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.
CVE-2026-55379
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.
CVE-2026-55379
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.p ...
ROS-20260817-80-0230
Уязвимость python-pillow
ROS-20260817-80-0227
Уязвимость python-pillow
ROS-20260817-73-0210
Уязвимость python-pillow
ROS-20260817-73-0207
Уязвимость python-pillow
GHSA-phj9-mv4w-65pm
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
GHSA-45hq-cxwh-f6vc
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55380 Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-55380 Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-55380 Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.p ... | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-55379 Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-55379 Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-55379 Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-55379 Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.p ... | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
ROS-20260817-80-0230 Уязвимость python-pillow | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
ROS-20260817-80-0227 Уязвимость python-pillow | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
ROS-20260817-73-0210 Уязвимость python-pillow | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
ROS-20260817-73-0207 Уязвимость python-pillow | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-phj9-mv4w-65pm Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()` | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-45hq-cxwh-f6vc Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу