Description
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.
INFO
Published Date :
2026-04-15T22:53:56.147Z
Last Modified :
2026-04-16T13:37:19.918Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-40192 vulnerability.
| Vendors | Products |
|---|---|
| Python |
|
| Python-pillow |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-40192.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact