CVE-2026-40192High· 7.5▾ TwilightPillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file coul…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.7%
Last analysed / modified upstream
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.
pillow >= 10.3.0, < 12.2.0Upgrade past the affected range:
pillow 12.2.0Affected packages:
pillow >= 10.3.0, < 12.2.0Patched in:
pillow 12.2.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-25990High· 7.5Pillow is a Python imaging library
CVE-2026-44432High· 7.5urllib3 is an HTTP client library for Python
CVE-2026-31958High· 7.5Tornado is a Python web framework and asynchronous networking library
CVE-2026-21441High· 7.5urllib3 is an HTTP client library for Python
CVE-2026-42587High· 7.5Netty is an asynchronous, event-driven network application framework
CVE-2026-12151High· 7.5undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)