---
id: CVE-2026-54060
title: >-
  python-pillow: Pillow: Denial of Service via excessive memory allocation when
  processing font files (CVE-2026-54060)
summary: >-
  A flaw was found in Pillow, a Python imaging library. When processing a
  specially crafted font file, the library's font compilation function does not
  adequately check for excessive memory allocation. This oversight allows a
  remote attacker…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-1050
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - exploit_intelligence
  - lightspeed_core
  - openshift_lightspeed
  - ai_inference_server
  - ansible_automation_platform 2
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - satellite 6
  - ansible_automation_platform_2_5_for_rhel 8
  - satellite_6_16_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - satellite_6_16_for_rhel 9
  - satellite_6_17_for_rhel 9
  - satellite_6_18_for_rhel 9
  - satellite_6_19_for_rhel 9
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_4
  - enterprise_linux_appstream_eus_extension_v_8_4
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_crb_v_8
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - ai_inference_server 3.4
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - enterprise_linux_ai 3.3
  - openshift_ai 3.4
  - quay 3.10
  - quay 3.12
  - quay 3.15
  - quay 3.16
  - quay 3.9
patched:
  - ansible_automation_platform_2_5_for_rhel 8
  - satellite_6_16_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - satellite_6_16_for_rhel 9
  - satellite_6_17_for_rhel 9
  - satellite_6_18_for_rhel 9
  - satellite_6_19_for_rhel 9
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_4
  - enterprise_linux_appstream_eus_extension_v_8_4
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_crb_v_8
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - ai_inference_server 3.4
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - enterprise_linux_ai 3.3
  - openshift_ai 3.4
  - quay 3.10
  - quay 3.12
  - quay 3.15
  - quay 3.16
  - quay 3.9
published: '2026-07-06'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T16:39:04+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54060.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54060.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-54060'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2497466'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-54060'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54060'
  - url: >-
      https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst
  - url: >-
      https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d
  - url: >-
      https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2
  - url: 'https://access.redhat.com/errata/RHSA-2026:50319'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50223'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50336'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50222'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50263'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50221'
  - url: 'https://access.redhat.com/errata/RHSA-2026:39127'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52551'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48760'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48759'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61628'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61627'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61629'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59518'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69468'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69466'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69467'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69469'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69464'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50479'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50340'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62336'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62335'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52968'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48933'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2254.yaml
  - url: 'https://github.com/python-pillow/Pillow'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00418
epssPercentile: 0.35669
aliases:
  - GHSA-5x94-69rx-g8h2
  - BIT-pillow-2026-54060
  - PYSEC-2026-2254
ecosystem: pip
ingestedAt: '2026-07-13T18:58:08.562Z'
---

## Overview

A flaw was found in Pillow, a Python imaging library. When processing a specially crafted font file, the library's font compilation function does not adequately check for excessive memory allocation. This oversight allows a remote attacker to trigger an unreasonable consumption of system memory, leading to a denial of service (DoS) for the application.

## Vendor advisories

- **RHSA-2026:50319** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50319)
- **RHSA-2026:50223** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50223)
- **RHSA-2026:50336** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50336)
- **RHSA-2026:50222** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50222)
- **RHSA-2026:50263** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50263)
- **RHSA-2026:50221** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50221)
- **RHSA-2026:39127** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-07-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:39127)
- **RHSA-2026:52551** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52551)
- **RHSA-2026:48760** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-07-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:48760)
- **RHSA-2026:48759** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-07-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:48759)
- **RHSA-2026:61628** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61628)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, … · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Exploit Intelligence, Lightspeed Core, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54060.json)

**python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files** — rated Important by Red Hat. Released 2026-07-06, updated 2026-09-21.

Affected:

- Exploit Intelligence
- Lightspeed Core
- OpenShift Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6

Fixed:

- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Satellite 6.16 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Satellite 6.16 for RHEL 9
- Red Hat Satellite 6.17 for RHEL 9
- Red Hat Satellite 6.18 for RHEL 9
- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream AUS (v.8.4)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- Red Hat Enterprise Linux AppStream AUS (v.8.6)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
- Red Hat Enterprise Linux AppStream E4S (v.8.8)
- Red Hat Enterprise Linux AppStream TUS (v.8.8)
- Red Hat Enterprise Linux CRB (v. 8)
- Red Hat AI Inference Server 3.2
- Red Hat AI Inference Server 3.3
- Red Hat AI Inference Server 3.4
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Enterprise Linux AI 3.3
- Red Hat OpenShift AI 3.4
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9

No fix planned:

- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Exploit Intelligence
- Lightspeed Core
- OpenShift Lightspeed
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6

Not affected:

- Red Hat Ansible Automation Platform 2.6 for RHEL 10
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Satellite 6.16 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Satellite 6.16 for RHEL 9
- Red Hat Satellite 6.17 for RHEL 9
- Red Hat Satellite 6.18 for RHEL 9
- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Ansible Automation Platform 2.6

## Remediation

For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50319
Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:50223
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50336

## Package advisory (CVE-2026-54060)

Affected packages:

- `pillow < 12.3.0`

Patched in:

- `pillow 12.3.0`

Source: https://osv.dev/vulnerability/GHSA-5x94-69rx-g8h2
