BIT-pillow-2026-40192

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/pillow/BIT-pillow-2026-40192.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-pillow-2026-40192
Aliases
Published
2026-04-18T08:46:42.614Z
Modified
2026-04-18T09:26:07.956866070Z
Summary
Pillow is vulnerable to a FITS GZIP decompression bomb
Details

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

Database specific
{
    "severity": "High",
    "cpes": [
        "cpe:2.3:a:python:pillow:*:*:*:*:*:python:*:*"
    ]
}
References

Affected packages

Bitnami / pillow

Package

Name
pillow
Purl
pkg:bitnami/pillow

Severity

  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
10.3.0
Fixed
12.2.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/pillow/BIT-pillow-2026-40192.json"