PT-2026-58106 · Pypi · Pillow

CVE-2026-59200

·

Published

2026-06-30

·

Updated

2026-08-31

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Pillow versions 5.1.0 through 12.2.x
Description The PdfParser.PdfStream.decode() function in PIL/PdfParser.py calls zlib.decompress() using the PDF stream Length field for the bufsize parameter without limiting the size of the decompressed output. This allows a specially crafted FlateDecode PDF stream to cause memory exhaustion, even when processing a small file.
Recommendations Update to version 12.3.0.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09901
BIT-PILLOW-2026-59200
CVE-2026-59200
ECHO-B776-8C4A-970E
GHSA-JJJ6-MW9F-P565
OESA-2026-3137
OESA-2026-3138
OESA-2026-3139
OESA-2026-3140
OESA-2026-3186
OPENSUSE-SU-2026:11283-1
OPENSUSE-SU-2026:21544-1
PYSEC-2026-3495
SUSE-SU-2026:23217-1
SUSE-SU-2026:23228-1
SUSE-SU-2026:3084-1
SUSE-SU-2026:3268-1

Affected Products

Pillow