CVE 8.7 HIGH

Pillow is vulnerable to a FITS GZIP decompression bomb_CVE-2026-40192

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

AI Analysis

Pillow is vulnerable to a FITS GZIP decompression bomb, which can cause unbounded memory consumption and lead to denial of service.

Basic Information

ID CVE-2026-40192
Source GitHub_M
Published Apr 15, 2026 at 22:53

Affected Product

Vendor python-pillow
Product Pillow
Version >= 10.3.0, < 12.2.0
Affected Versions python-pillow Pillow >= 10.3.0, < 12.2.0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Python Pillow Project
Product Pillow
Version 10.3.0 to 12.1.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.