BIT-pillow-2026-42308

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/pillow/BIT-pillow-2026-42308.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-pillow-2026-42308
Aliases
Published
2026-05-12T08:54:01.462Z
Modified
2026-05-27T13:56:18.230226284Z
Summary
Pillow: Integer overflow when processing fonts
Details

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:python:pillow:*:*:*:*:*:python:*:*"
    ]
}
References

Affected packages

Bitnami / pillow

Package

Name
pillow
Purl
pkg:bitnami/pillow

Severity

  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
12.2.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/pillow/BIT-pillow-2026-42308.json"