---
id: CVE-2026-40192
title: Pillow is a Python imaging library
summary: >-
  Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not
  limit the amount of GZIP-compressed data read when decoding a FITS image,
  making them vulnerable to decompression bomb attacks. A specially crafted FITS
  file coul…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-770
  - CWE-409
vendor: python
product: pillow
affected:
  - 'pillow >= 10.3.0, < 12.2.0'
patched:
  - pillow 12.2.0
published: '2026-04-15'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:20:01.390'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40192'
references:
  - url: >-
      https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628
    label: security-advisories@github.com
  - url: 'https://github.com/python-pillow/Pillow/pull/9521'
    label: security-advisories@github.com
  - url: >-
      https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j
    label: security-advisories@github.com
  - url: >-
      https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:16008'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16009'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16030'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16174'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17609'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17611'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19375'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19712'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21017'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22465'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22629'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22840'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:23361'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24761'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24762'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24853'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24866'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24977'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27076'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:34365'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:34366'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:34368'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37275'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:57387'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:61627'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:61628'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:61629'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-40192'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2458856'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-40192'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40192'
  - url: 'https://github.com/python-pillow/Pillow'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - osv
  - pip
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-04-16T13:37:11.864898Z'
scores:
  nvd: 7.5
  cna: 8.7
  vendor: 7.5
  osv: 7.5
epss: 0.00868
epssPercentile: 0.56949
ingestedAt: '2026-07-01T15:50:58.773Z'
aliases:
  - GHSA-whj4-6x5x-4v2j
  - BIT-pillow-2026-40192
  - PYSEC-2026-2250
ecosystem: pip
---

## Overview

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

## Affected

- `pillow >= 10.3.0, < 12.2.0`

## Remediation

Upgrade past the affected range:

- `pillow 12.2.0`

## Vendor advisories

- **RHSA-2026:24761** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24761)
- **RHSA-2026:27076** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-06-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:27076)
- **RHSA-2026:24762** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24762)
- **RHSA-2026:34366** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34366)
- **RHSA-2026:34368** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34368)
- **RHSA-2026:34365** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34365)
- **RHSA-2026:61628** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61628)
- **RHSA-2026:61627** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61627)
- **RHSA-2026:61629** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61629)
- **RHSA-2026:16008** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16008)
- **RHSA-2026:16030** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16030)
- **Red Hat VEX** · Important · affected: Lightspeed Core, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · no fix planned: Red Hat Enterprise Linux 7, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 8, … · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json)

## Package advisory (CVE-2026-40192)

Affected packages:

- `pillow >= 10.3.0, < 12.2.0`

Patched in:

- `pillow 12.2.0`

Source: https://osv.dev/vulnerability/GHSA-whj4-6x5x-4v2j
