VYPR
High severity7.5NVD Advisory· Published Apr 15, 2026· Updated Apr 22, 2026

CVE-2026-40192

CVE-2026-40192

Description

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pillowPyPI
>= 10.3.0, < 12.2.012.2.0

Affected products

14

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.