PT-2026-58091 · Pypi · Pillow
CVE-2026-59203
·
Published
2026-06-23
·
Updated
2026-08-12
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Pillow versions 12.0.0 through 12.2.0
Description
The EPS parser in
PIL/EpsImagePlugin.py accepts a negative byte count within the %%BeginBinary directive. A specially crafted EPS file can trigger the Image.open() function to seek backwards to the same directive, resulting in an infinite loop during parsing.Recommendations
Update to version 12.3.0.
Exploit
Fix
DoS
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pillow