---
id: CVE-2026-59200
title: 'Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)'
summary: >-
  A flaw was found in Pillow, a Python imaging library. A remote attacker could
  exploit a vulnerability in the PdfParser.PdfStream.decode() function when
  processing a crafted FlateDecode PDF stream. By providing a specially designed
  PDF file…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-409
  - CWE-400
  - CWE-770
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - lightspeed_core
  - openshift_lightspeed
  - ai_inference_server
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - ai_inference_server 3.3
  - ai_inference_server 3.4
  - enterprise_linux_ai 3.3
  - openshift_ai 3.4
  - quay 3.10
  - quay 3.12
  - quay 3.14
  - quay 3.15
  - quay 3.16
  - quay 3.9
patched:
  - ai_inference_server 3.3
  - ai_inference_server 3.4
  - enterprise_linux_ai 3.3
  - openshift_ai 3.4
  - quay 3.10
  - quay 3.12
  - quay 3.14
  - quay 3.15
  - quay 3.16
  - quay 3.9
published: '2026-07-14'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T05:54:54+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59200.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59200.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59200'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2500060'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59200'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59200'
  - url: >-
      https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09
  - url: 'https://github.com/python-pillow/Pillow/pull/9718'
  - url: 'https://github.com/python-pillow/Pillow/releases/tag/12.3.0'
  - url: >-
      https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565
  - url: 'https://access.redhat.com/errata/RHSA-2026:59518'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70996'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69468'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69466'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70965'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70979'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69467'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70995'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69469'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70969'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69464'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62336'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62335'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52968'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70267'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48933'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69255'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50931'
  - url: 'https://github.com/python-pillow/Pillow'
  - url: 'https://github.com/advisories/GHSA-jjj6-mw9f-p565'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - ghsa
epss: 0.00655
epssPercentile: 0.49151
aliases:
  - GHSA-jjj6-mw9f-p565
  - BIT-pillow-2026-59200
  - PYSEC-2026-3495
ecosystem: pip
ingestedAt: '2026-07-20T23:44:02.467Z'
---

## Overview

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the PdfParser.PdfStream.decode() function when processing a crafted FlateDecode PDF stream. By providing a specially designed PDF file, the attacker could cause the application to exhaust available memory, leading to a denial of service (DoS).

## Vendor advisories

- **RHSA-2026:59518** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:59518)
- **RHSA-2026:70996** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70996)
- **RHSA-2026:69468** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69468)
- **RHSA-2026:69466** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69466)
- **RHSA-2026:70965** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70965)
- **RHSA-2026:70979** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70979)
- **RHSA-2026:69467** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69467)
- **RHSA-2026:70995** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70995)
- **RHSA-2026:69469** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69469)
- **RHSA-2026:70969** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70969)
- **RHSA-2026:69464** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69464)
- **Red Hat VEX** · Important · affected: Lightspeed Core, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Lightspeed Core, OpenShift Lightspeed, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59200.json)
- **RHSA-2026:62336** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62336)
- **RHSA-2026:62335** · Red Hat · fixed in: Red Hat Enterprise Linux AI 3.3 · released 2026-09-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:62335)
- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **RHSA-2026:53520** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53520)
- **RHSA-2026:52968** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52968)
- **RHSA-2026:48933** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48933)
- **RHSA-2026:69255** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69255)
- **RHSA-2026:50931** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-08-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:50931)

**Pillow: Pillow: Denial of service via crafted PDF stream** — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-24.

Affected:

- Lightspeed Core
- OpenShift Lightspeed
- Red Hat AI Inference Server
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Fixed:

- Red Hat AI Inference Server 3.3
- Red Hat AI Inference Server 3.4
- Red Hat Enterprise Linux AI 3.3
- Red Hat OpenShift AI 3.4
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.14
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9

No fix planned:

- Red Hat AI Inference Server
- Lightspeed Core
- OpenShift Lightspeed
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)

Not affected:

- Red Hat Enterprise Linux AI 3.3
- Red Hat OpenShift AI 3.4
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.14
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9
- Exploit Intelligence
- OpenShift Lightspeed

## Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:59518 https://access.redhat.com/errata/RHSA-2026:59518
For more information visit https://access.redhat.com/errata/RHSA-2026:70996 https://access.redhat.com/errata/RHSA-2026:70996
For more information visit https://access.redhat.com/errata/RHSA-2026:69468 https://access.redhat.com/errata/RHSA-2026:69468

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-59200)

Affected packages:

- `pillow >= 5.1.0, < 12.3.0`

Patched in:

- `pillow 12.3.0`

Source: https://osv.dev/vulnerability/GHSA-jjj6-mw9f-p565
