PT-2026-32580 · Pypi+2 · Pillow+2

CVE-2026-40192

·

Published

2024-03-25

·

Updated

2026-08-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Pillow versions 10.3.0 through 12.1.1
Description Lack of limits on the amount of GZIP-compressed data read when decoding a FITS image allows for decompression bomb attacks. A specially crafted FITS file can cause unbounded memory consumption, resulting in a denial of service through an OOM (Out of Memory) crash or severe performance degradation.
Recommendations Update to version 12.2.0. As a temporary workaround, only open specific image formats, excluding FITS.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05627
BIT-PILLOW-2026-40192
CLEANSTART-2026-EN66750
CLEANSTART-2026-FG72002
CLEANSTART-2026-RF67070
CVE-2026-40192
ECHO-1C52-724C-58AD
GHSA-WHJ4-6X5X-4V2J
OESA-2026-2064
OESA-2026-2065
OESA-2026-2066
OPENSUSE-SU-2026:10575-1
OPENSUSE-SU-2026:20617-1
PYSEC-2026-2250
RHSA-2026:24761
RHSA-2026:24762
RHSA-2026:27076
RHSA-2026:34365
RHSA-2026:34366
RHSA-2026:34368
SUSE-SU-2026:21382-1
USN-8211-1

Affected Products

Pillow
Red Os
Ubuntu