---
id: CVE-2026-55379
title: >-
  python-pillow: Pillow: Denial of Service via crafted BDF font file
  (CVE-2026-55379)
summary: >-
  A flaw was found in Pillow, a Python imaging library. This vulnerability
  allows a remote attacker to cause a Denial of Service (DoS) by providing a
  specially crafted BDF font file. The library's image processing function fails
  to properly …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-770
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - exploit_intelligence
  - lightspeed_core
  - openshift_lightspeed
  - ai_inference_server
  - ansible_automation_platform 2
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - satellite 6
  - ansible_automation_platform_2_5_for_rhel 8
  - satellite_6_16_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - satellite_6_16_for_rhel 9
  - satellite_6_17_for_rhel 9
  - satellite_6_18_for_rhel 9
  - satellite_6_19_for_rhel 9
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_4
  - enterprise_linux_appstream_eus_extension_v_8_4
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_crb_v_8
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - ai_inference_server 3.4
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - enterprise_linux_ai 3.3
  - openshift_ai 3.4
  - quay 3.10
  - quay 3.12
  - quay 3.14
  - quay 3.15
  - quay 3.16
  - quay 3.9
patched:
  - ansible_automation_platform_2_5_for_rhel 8
  - satellite_6_16_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - satellite_6_16_for_rhel 9
  - satellite_6_17_for_rhel 9
  - satellite_6_18_for_rhel 9
  - satellite_6_19_for_rhel 9
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_4
  - enterprise_linux_appstream_eus_extension_v_8_4
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_crb_v_8
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - ai_inference_server 3.4
  - ansible_automation_platform 2.5
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - enterprise_linux_ai 3.3
  - openshift_ai 3.4
  - quay 3.10
  - quay 3.12
  - quay 3.14
  - quay 3.15
  - quay 3.16
  - quay 3.9
published: '2026-07-06'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T05:56:57+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55379.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55379.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-55379'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2497452'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-55379'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55379'
  - url: >-
      https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst
  - url: >-
      https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d
  - url: >-
      https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc
  - url: 'https://access.redhat.com/errata/RHSA-2026:50319'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50223'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50336'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50222'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50263'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50221'
  - url: 'https://access.redhat.com/errata/RHSA-2026:39127'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52551'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48760'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48759'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61628'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61627'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61629'
  - url: 'https://access.redhat.com/errata/RHSA-2026:59518'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70996'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69468'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69466'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70965'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70979'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69467'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70995'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69469'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69464'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50357'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50479'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50340'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62336'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62335'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52968'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2255.yaml
  - url: 'https://github.com/python-pillow/Pillow'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00649
epssPercentile: 0.48849
aliases:
  - GHSA-45hq-cxwh-f6vc
  - BIT-pillow-2026-55379
  - PYSEC-2026-2255
ecosystem: pip
ingestedAt: '2026-07-13T18:58:08.581Z'
---

## Overview

A flaw was found in Pillow, a Python imaging library. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted BDF font file. The library's image processing function fails to properly validate dimensions from the font file, bypassing a critical security check designed to prevent excessive memory usage. This oversight can lead to the system consuming an unreasonable amount of memory, making it unavailable to legitimate users.

## Vendor advisories

- **RHSA-2026:50319** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50319)
- **RHSA-2026:50223** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50223)
- **RHSA-2026:50336** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50336)
- **RHSA-2026:50222** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50222)
- **RHSA-2026:50263** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50263)
- **RHSA-2026:50221** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50221)
- **RHSA-2026:39127** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-07-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:39127)
- **RHSA-2026:52551** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52551)
- **RHSA-2026:48760** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-07-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:48760)
- **RHSA-2026:48759** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-07-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:48759)
- **RHSA-2026:61628** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61628)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, … · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Exploit Intelligence, Lightspeed Core, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55379.json)

**python-pillow: Pillow: Denial of Service via crafted BDF font file** — rated Important by Red Hat. Released 2026-07-06, updated 2026-09-24.

Affected:

- Exploit Intelligence
- Lightspeed Core
- OpenShift Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6

Fixed:

- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Satellite 6.16 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Satellite 6.16 for RHEL 9
- Red Hat Satellite 6.17 for RHEL 9
- Red Hat Satellite 6.18 for RHEL 9
- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream AUS (v.8.4)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- Red Hat Enterprise Linux AppStream AUS (v.8.6)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
- Red Hat Enterprise Linux AppStream E4S (v.8.8)
- Red Hat Enterprise Linux AppStream TUS (v.8.8)
- Red Hat Enterprise Linux CRB (v. 8)
- Red Hat AI Inference Server 3.2
- Red Hat AI Inference Server 3.3
- Red Hat AI Inference Server 3.4
- Red Hat Ansible Automation Platform 2.5
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Enterprise Linux AI 3.3
- Red Hat OpenShift AI 3.4
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.14
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9

No fix planned:

- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Exploit Intelligence
- Lightspeed Core
- OpenShift Lightspeed
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6

Not affected:

- Red Hat Ansible Automation Platform 2.6 for RHEL 10
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Satellite 6.16 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Satellite 6.16 for RHEL 9
- Red Hat Satellite 6.17 for RHEL 9
- Red Hat Satellite 6.18 for RHEL 9
- Red Hat Satellite 6.19 for RHEL 9
- Red Hat Ansible Automation Platform 2.5

## Remediation

For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50319
Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:50223
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50336

Workarounds / mitigations:

- Do not load BDF font files from untrusted sources. Applications that only process standard image formats (PNG, JPEG, etc.) and do not use BdfFontFile or ImageFont.load() with BDF files are not affected.

## Package advisory (CVE-2026-55379)

Affected packages:

- `pillow < 12.3.0`

Patched in:

- `pillow 12.3.0`

Source: https://osv.dev/vulnerability/GHSA-45hq-cxwh-f6vc
