VYPR
High severity7.5NVD Advisory· Published Jul 14, 2026· Updated Jul 21, 2026

CVE-2026-59200

CVE-2026-59200

Description

Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
PillowPyPI
>= 5.1.0, < 12.3.012.3.0

Affected products

21

Patches

Vulnerability mechanics

References

6

News mentions

1