cbcvebase.
CVE-2026-42308
published 2026-05-09

CVE-2026-42308: Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the…

medium5.1CVSS 4.0
AVLACLATNPRNUINVCNVINVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.

Affected

68 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platform-25lightspeed-chatbot-rhel8
ansible-automation-platform-26hub-rhel9
ansible-automation-platform-26lightspeed-chatbot-rhel9
ansible-automation-platformautomation-dashboard-rhel9
debianpython3.11
debianpython3.13
debianpython3.14
debianpython3.9
devspacescode-rhel9
devspacespluginregistry-rhel9
exploit-intelligence-tech-previewvulnerability-analysis-rhel9
openshift-lightspeedlightspeed-ocp-rag-rhel9
openshift-lightspeedlightspeed-service-api-rhel9
pen-drivepen-drive-scanner-rhel9
python-pillowpillow< 12.2.012.2.0
pythonpillow< 12.2.012.2.0
pythonpillow>= 0 < 12.2.012.2.0
pythonpython
python36_3.6python36
python39-devel_3.9python39
quayquay-rhel8
quayquay-rhel9
rhaiismodel-opt-cuda-rhel9
rhaiisvllm-cpu-rhel9
rhaiisvllm-cuda-rhel9