Threat Advisory

Pillow Compile Vulnerability Lets Attackers Create Decompression Bombs

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple high- and medium-severity security vulnerabilities have been identified in the Pillow Python imaging library, affecting versions prior to 12.3.0. These vulnerabilities impact image parsing, font processing, image encoding, image manipulation, PDF processing, and Windows image viewing functionality. Successful exploitation could allow attackers to disclose sensitive memory, perform heap corruption, execute arbitrary operating system commands on Windows, bypass decompression bomb protections, or cause denial-of-service (DoS) conditions through excessive memory or CPU consumption. Applications that process untrusted image, PDF, or font files are particularly at risk.

• CVE-2026-54058 with a CVSS score of 8.3 – An out-of-bounds read vulnerability in the McIdas image plugin allows attacker-controlled row stride values to disclose adjacent process memory or trigger application crashes.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple high- and medium-severity security vulnerabilities have been identified in the Pillow Python imaging library, affecting versions prior to 12.3.0. These vulnerabilities impact image parsing, font processing, image encoding, image manipulation, PDF processing, and Windows image viewing functionality. Successful exploitation could allow attackers to disclose sensitive memory, perform heap corruption, execute arbitrary operating system commands on Windows, bypass decompression bomb protections, or cause denial-of-service (DoS) conditions through excessive memory or CPU consumption. Applications that process untrusted image, PDF, or font files are particularly at risk.

• CVE-2026-54058 with a CVSS score of 8.3 – An out-of-bounds read vulnerability in the McIdas image plugin allows attacker-controlled row stride values to disclose adjacent process memory or trigger application crashes.[emaillocker id="1283"]

• CVE-2026-54059 with a CVSS score of 7.5 – A decompression bomb protection bypass in the PCF font loader allows crafted font files to trigger excessive memory allocation, resulting in denial of service.

• CVE-2026-54060 with a CVSS score of 7.5 – A missing decompression bomb check in FontFile.compile() enables excessive memory allocation through malicious font files, leading to denial of service.

• CVE-2026-55379 with a CVSS score of 7.5 – A decompression bomb protection bypass in the BDF font loader permits crafted font files to consume excessive system memory, causing denial of service.

• CVE-2026-55380 with a CVSS score of 7.5 – Missing decompression bomb validation in the GD image loader allows specially crafted image files to trigger excessive memory consumption and service disruption.

• CVE-2026-55798 with a CVSS score of 8.4 – An OS command injection vulnerability in the Windows image viewer allows specially crafted file paths to execute arbitrary operating system commands.

• CVE-2026-59197 with a CVSS score of 8.2 – A heap out-of-bounds write in the ImageFilter.RankFilter API can result in memory corruption, application crashes, or potential code execution.

• CVE-2026-59198 with a CVSS score of 6.5 – A heap out-of-bounds read in the TGA RLE encoder can disclose adjacent process memory through crafted image generation.

• CVE-2026-59199 with a CVSS score of 7.5 – A heap out-of-bounds write in Image.paste() and Image.crop() may lead to memory corruption and application instability.

• CVE-2026-59200 with a CVSS score of 7.5 – A decompression bomb vulnerability in PdfParser.PdfStream.decode() enables attackers to exhaust system memory using specially crafted PDF files, resulting in denial of service.

• CVE-2026-59203 with a CVSS score of 5.3 – An infinite loop vulnerability in the EPS parser can cause excessive CPU utilization and denial of service through crafted EPS files.

• CVE-2026-59204 with a CVSS score of 8.7 – A flaw in JPEG2000 tiled image decoding allows uncontrolled memory growth, enabling denial-of-service attacks through memory exhaustion.

• CVE-2026-59205 with a CVSS score of 7.5 – A controlled heap out-of-bounds write in ImageCmsTransform.apply() can cause heap corruption when processing images with mismatched output modes.

Successful exploitation of these vulnerabilities could result in information disclosure, heap memory corruption, arbitrary command execution on Windows systems, excessive memory or CPU consumption, application crashes, and denial of service. Organizations using affected versions of Pillow should upgrade to version 12.3.0 or later as soon as possible and avoid processing untrusted image, PDF, or font files until remediation measures have been applied.

RECOMMENDATION:

We recommend you to update Pillow to version 12.3.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu