Количество 8
Количество 8
CVE-2026-40192
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.
CVE-2026-40192
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.
CVE-2026-40192
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.
CVE-2026-40192
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did ...
openSUSE-SU-2026:20617-1
Security update for python-Pillow
GHSA-whj4-6x5x-4v2j
FITS GZIP decompression bomb in Pillow
ROS-20260713-73-0019
Уязвимость python-pillow
BDU:2026-05627
Уязвимость библиотеки для работы с изображениями Pillow, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-40192 Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-40192 Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-40192 Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-40192 Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did ... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
openSUSE-SU-2026:20617-1 Security update for python-Pillow | 1% Низкий | 3 месяца назад | ||
GHSA-whj4-6x5x-4v2j FITS GZIP decompression bomb in Pillow | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
ROS-20260713-73-0019 Уязвимость python-pillow | CVSS3: 7.5 | 1% Низкий | 20 дней назад | |
BDU:2026-05627 Уязвимость библиотеки для работы с изображениями Pillow, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу