PT-2026-58106 · Pypi · Pillow
CVE-2026-59200
·
Published
2026-06-30
·
Updated
2026-08-31
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Pillow versions 5.1.0 through 12.2.x
Description
The
PdfParser.PdfStream.decode() function in PIL/PdfParser.py calls zlib.decompress() using the PDF stream Length field for the bufsize parameter without limiting the size of the decompressed output. This allows a specially crafted FlateDecode PDF stream to cause memory exhaustion, even when processing a small file.Recommendations
Update to version 12.3.0.
Exploit
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pillow