← Vulnerability feed

Vulnerability record · CVE-2026-40192 · published 15 April 2026

CVE-2026-40192: Python pillow uncontrolled resource consumption vulnerability

Python · Pillow

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

8.7 CVSS 4.0 High EPSS 0.87% · top 42.9% CWE-400 · Uncontrolled resource consumptionCWE-770 · Allocation without limits
8.7CVSS 4.0 base score
0.87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
35References
10 Sep 2026Last modified by NVD

Description

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628 Patch
https://github.com/python-pillow/Pillow/pull/9521 Issue TrackingPatch
https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j MitigationPatchVendor Advisory
https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb Release Notes
https://access.redhat.com/errata/RHSA-2026:16008
https://access.redhat.com/errata/RHSA-2026:16009
https://access.redhat.com/errata/RHSA-2026:16030
https://access.redhat.com/errata/RHSA-2026:16174
https://access.redhat.com/errata/RHSA-2026:17609
https://access.redhat.com/errata/RHSA-2026:17611
https://access.redhat.com/errata/RHSA-2026:19375
https://access.redhat.com/errata/RHSA-2026:19712
https://access.redhat.com/errata/RHSA-2026:21017
https://access.redhat.com/errata/RHSA-2026:22465
https://access.redhat.com/errata/RHSA-2026:22629
https://access.redhat.com/errata/RHSA-2026:22840
https://access.redhat.com/errata/RHSA-2026:23361
https://access.redhat.com/errata/RHSA-2026:24761
https://access.redhat.com/errata/RHSA-2026:24762
https://access.redhat.com/errata/RHSA-2026:24853
https://access.redhat.com/errata/RHSA-2026:24866
https://access.redhat.com/errata/RHSA-2026:24977
https://access.redhat.com/errata/RHSA-2026:27076
https://access.redhat.com/errata/RHSA-2026:34365
https://access.redhat.com/errata/RHSA-2026:34366
https://access.redhat.com/errata/RHSA-2026:34368
https://access.redhat.com/errata/RHSA-2026:37275
https://access.redhat.com/errata/RHSA-2026:57387
https://access.redhat.com/errata/RHSA-2026:61627
https://access.redhat.com/errata/RHSA-2026:61628
https://access.redhat.com/errata/RHSA-2026:61629
https://access.redhat.com/errata/RHSA-2026:65126
https://access.redhat.com/security/cve/CVE-2026-40192
https://bugzilla.redhat.com/show_bug.cgi?id=2458856
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json

Track CVE-2026-40192 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-3007Python pillow os command injection vulnerabilityPython Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in un…EPSS 12%9.8CVE-2022-30595Python pillow out-of-bounds write vulnerabilitylibImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.EPSS 2.3%9.8CVE-2022-22817Python pillow vulnerabilityPIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expressi…EPSS 3.3%9.8CVE-2021-34552Python pillow classic buffer overflow vulnerabilityPillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert funct…EPSS 3.2%9.8CVE-2021-25289Python pillow out-of-bounds write vulnerabilityAn issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain inte…EPSS 2.3%9.8CVE-2020-5311Python pillow classic buffer overflow vulnerabilitylibImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.EPSS 4.2%9.8CVE-2020-5312Python pillow classic buffer overflow vulnerabilitylibImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.EPSS 3.7%9.8CVE-2016-4009Python pillow memory buffer overflow vulnerabilityInteger overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecifie…EPSS 7.9%

Source: NIST National Vulnerability Database (record CVE-2026-40192), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.