CVE-2026-42308
published 2026-05-09CVE-2026-42308: Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.6th percentile
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-25 | lightspeed-chatbot-rhel8 | — | — |
| ansible-automation-platform-26 | hub-rhel9 | — | — |
| ansible-automation-platform-26 | lightspeed-chatbot-rhel9 | — | — |
| ansible-automation-platform | automation-dashboard-rhel9 | — | — |
| debian | python3.11 | — | — |
| debian | python3.13 | — | — |
| debian | python3.14 | — | — |
| debian | python3.9 | — | — |
| devspaces | code-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| openshift-lightspeed | lightspeed-ocp-rag-rhel9 | — | — |
| openshift-lightspeed | lightspeed-service-api-rhel9 | — | — |
| pen-drive | pen-drive-scanner-rhel9 | — | — |
| python-pillow | pillow | < 12.2.0 | 12.2.0 |
| python | pillow | < 12.2.0 | 12.2.0 |
| python | pillow | >= 0 < 12.2.0 | 12.2.0 |
| python | python | — | — |
| python36_3.6 | python36 | — | — |
| python39-devel_3.9 | python39 | — | — |
| quay | quay-rhel8 | — | — |
| quay | quay-rhel9 | — | — |
| rhaiis | model-opt-cuda-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-cuda-rhel9 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.05.1MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_ubuntu5.5MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2026-06-08·CVSS 5.5
CVE-2026-42310 [MEDIUM] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled large glyph advance
values in fonts. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. (CVE-2026-42308)
It was discovered that Pillow incorrectly handled nested coordinate lists
in certain APIs. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. This issue only affected Ubuntu
25.10 and Ubuntu 26.04 LTS. (CVE-2026-42309)
It was discovered that Pillow incorrectly handled certain malformed PDF
files. An attacker could possibly use this issue to cause Pillow to use
excessive resources, leading to a denial of service. (CVE-2026-42310)
It was discovered th
Red Hat
Pillow: python: Pillow: Denial of Service via integer overflow in font processing
vendor_redhat·2026-05-09·CVSS 5.1
CVE-2026-42308 [MEDIUM] CWE-190 Pillow: python: Pillow: Denial of Service via integer overflow in font processing
Pillow: python: Pillow: Denial of Service via integer overflow in font processing
A flaw was found in Pillow, a Python imaging library. If a font advances for each glyph by an exceeding large amount, an integer overflow can occur when Pillow tracks the current position. This could lead to a denial of service (DoS) condition, making the application unavailable.
Mitigation: To mitigate this issue, ensure that applications utilizing the Pillow library do not process untrusted or maliciously crafted font files. Additionally, consider running applications that process image data in a sandboxed environment to limit potential impact. Reloading or restarting affected services may be required for changes to take effect.
Package: exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 (Exp
VulDB
Pillow up to 12.1.x integer overflow (GHSA-wjx4-4jcj-g98j / EUVD-2026-28900)
vuldb·2026-05-09·CVSS 5.1
CVE-2026-42308 [MEDIUM] Pillow up to 12.1.x integer overflow (GHSA-wjx4-4jcj-g98j / EUVD-2026-28900)
A vulnerability identified as problematic has been detected in Pillow up to 12.1.x. Affected is an unknown function. Performing a manipulation results in integer overflow.
This vulnerability is reported as CVE-2026-42308. The attack requires a local approach. No exploit exists.
You should upgrade the affected component.
GHSA
Pillow has an integer overflow when processing fonts
ghsa·2026-05-04
CVE-2026-42308 [MEDIUM] CWE-190 Pillow has an integer overflow when processing fonts
Pillow has an integer overflow when processing fonts
If a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This has been fixed.
No detection rules found.
No public exploits indexed.
2026-05-09
Published