PT-2026-58091 · Pypi · Pillow

CVE-2026-59203

·

Published

2026-06-23

·

Updated

2026-08-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pillow versions 12.0.0 through 12.2.0
Description The EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count within the %%BeginBinary directive. A specially crafted EPS file can trigger the Image.open() function to seek backwards to the same directive, resulting in an infinite loop during parsing.
Recommendations Update to version 12.3.0.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09902
BIT-PILLOW-2026-59203
CVE-2026-59203
ECHO-9F30-2662-0F87
GHSA-PG7V-JWJ7-P798
PYSEC-2026-3452

Affected Products

Pillow