PT-2026-55964 · Pypi+2 · Pillow+2

·

CVE-2026-55379

·

Published

2026-07-06

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pillow versions prior to 12.3.0
Description The bdf char() function in PIL/BdfFontFile.py reads the BBX width and height fields from a BDF font file and passes these attacker-controlled dimensions to Image.new() without invoking Image. decompression bomb check(). This bypasses the documented decompression bomb protection, which is a security mechanism designed to prevent the processing of maliciously crafted files that expand to an enormous size in memory, leading to excessive memory allocation.
Recommendations Update to version 12.3.0.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:39127
BIT-PILLOW-2026-55379
CVE-2026-55379
ECHO-F7CD-A473-7E12
GHSA-45HQ-CXWH-F6VC
OESA-2026-3137
OESA-2026-3138
OESA-2026-3139
OESA-2026-3140
OESA-2026-3141
OPENSUSE-SU-2026:11261-1
OPENSUSE-SU-2026:21296-1
PYSEC-2026-2255
RHSA-2026:50221
RHSA-2026:50222
RHSA-2026:50223
RHSA-2026:50263
RHSA-2026:50319
RHSA-2026:50336
RHSA-2026:52551
SUSE-SU-2026:22626-1
SUSE-SU-2026:2875-1
SUSE-SU-2026:3268-1

Affected Products

Pillow
Red Os
Rocky Linux