Vulnerability record · CVE-2021-28677 · published 2 June 2021
CVE-2021-28677: Python pillow vulnerability
Python · Pillow
An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.
Description
An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/python-pillow/Pillow/pull/5377 | PatchThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2021/07/msg00018.html | Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MQHA5HAIBOYI3R6HDWCLAGF | |
| https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#cve-2021-28677-fix-eps-dos-on-open | Third Party Advisory |
| https://security.gentoo.org/glsa/202107-33 | Third Party Advisory |
| https://github.com/python-pillow/Pillow/pull/5377 | PatchThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2021/07/msg00018.html | Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MQHA5HAIBOYI3R6HDWCLAGF | |
| https://pillow.readthedocs.io/en/stable/releasenotes/8.2.0.html#cve-2021-28677-fix-eps-dos-on-open | Third Party Advisory |
| https://security.gentoo.org/glsa/202107-33 | Third Party Advisory |
Track CVE-2021-28677 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-28677), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.