---
id: CVE-2026-42308
title: >-
  Pillow: Pillow: Denial of Service via integer overflow in font processing
  (CVE-2026-42308)
summary: >-
  A flaw was found in Pillow, a Python imaging library. If a font advances for
  each glyph by an exceeding large amount, an integer overflow can occur when
  Pillow tracks the current position. This could lead to a denial of service
  (DoS) condi…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-190
vendor: Red Hat
product: Red Hat Enterprise Linux 8
affected:
  - exploit_intelligence
  - openshift_lightspeed
  - pen_drive_powered_by_red_hat_lightspeed
  - ai_inference_server
  - ansible_automation_platform 2
  - enterprise_linux 10
  - enterprise_linux 6
  - enterprise_linux 7
  - enterprise_linux 8
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - openshift_dev_spaces
  - quay 3
  - satellite 6
  - ai_inference_server 3.3
  - ai_inference_server 3.4
patched:
  - ai_inference_server 3.3
  - ai_inference_server 3.4
published: '2026-05-09'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:31:50+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42308.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42308.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42308'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2468457'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-42308'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42308'
  - url: 'https://github.com/python-pillow/Pillow/releases/tag/12.2.0'
  - url: >-
      https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j
  - url: 'https://access.redhat.com/errata/RHSA-2026:16008'
  - url: 'https://access.redhat.com/errata/RHSA-2026:16030'
  - url: 'https://access.redhat.com/errata/RHSA-2026:16009'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57387'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml
  - url: 'https://github.com/python-pillow/Pillow'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00159
epssPercentile: 0.04244
aliases:
  - GHSA-wjx4-4jcj-g98j
  - BIT-pillow-2026-42308
  - PYSEC-2026-165
ecosystem: pip
scores:
  vendor: 6.2
  osv: 5.5
ingestedAt: '2026-09-12T03:13:01.736Z'
---

## Overview

A flaw was found in Pillow, a Python imaging library. If a font advances for each glyph by an exceeding large amount, an integer overflow can occur when Pillow tracks the current position. This could lead to a denial of service (DoS) condition, making the application unavailable.

## Vendor advisories

- **RHSA-2026:16008** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16008)
- **RHSA-2026:16030** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16030)
- **RHSA-2026:16009** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16009)
- **RHSA-2026:57387** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57387)
- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, OpenShift Lightspeed, Pen Drive Powered by Red Hat Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, … · no fix planned: Red Hat Enterprise Linux 9, Exploit Intelligence, OpenShift Lightspeed, Pen Drive Powered by Red Hat Lightspeed, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42308.json)

**Pillow: Pillow: Denial of Service via integer overflow in font processing** — rated Moderate by Red Hat. Released 2026-05-09, updated 2026-09-18.

Affected:

- Exploit Intelligence
- OpenShift Lightspeed
- Pen Drive Powered by Red Hat Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Dev Spaces
- Red Hat Quay 3
- Red Hat Satellite 6

Fixed:

- Red Hat AI Inference Server 3.3
- Red Hat AI Inference Server 3.4

No fix planned:

- Red Hat Enterprise Linux 9
- Exploit Intelligence
- OpenShift Lightspeed
- Pen Drive Powered by Red Hat Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Dev Spaces
- Red Hat Quay 3
- Red Hat Satellite 6

## Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:16008 https://access.redhat.com/errata/RHSA-2026:16008
For more information visit https://access.redhat.com/errata/RHSA-2026:16030 https://access.redhat.com/errata/RHSA-2026:16030
For more information visit https://access.redhat.com/errata/RHSA-2026:16009 https://access.redhat.com/errata/RHSA-2026:16009

Workarounds / mitigations:

- To mitigate this issue, ensure that applications utilizing the Pillow library do not process untrusted or maliciously crafted font files. Additionally, consider running applications that process image data in a sandboxed environment to limit potential impact. Reloading or restarting affected services may be required for changes to take effect.

## Package advisory (CVE-2026-42308)

Affected packages:

- `pillow < 12.2.0`

Patched in:

- `pillow 12.2.0`

Source: https://osv.dev/vulnerability/GHSA-wjx4-4jcj-g98j
