CVE-2026-40192
HIGHPillow is vulnerable to a FITS GZIP decompression bomb
Title source: cnaDescription
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.
Scores
CVSS v3
7.5
EPSS
0.0002
EPSS Percentile
3.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-400
CWE-770
Status
published
Products (3)
pypi/pillow
10.3.0 - 12.2.0PyPI
python/pillow
10.3.0 - 12.2.0
python-pillow/Pillow
>= 10.3.0, < 12.2.0
Published
Apr 15, 2026
Tracked Since
Apr 16, 2026