<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T07:29:49.232768+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:39127</id>
    <title>ALSA-2026:39127 — Important: python-pillow security update</title>
    <updated>2026-10-04T07:29:50.424283+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python3-pillow, AlmaLinux:8: python3-pillow-devel, AlmaLinux:8: python3-pillow-doc, AlmaLinux:8: python3-pillow-tk</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* python-pillow: Pillow: Denial of Service via crafted BDF font file (CVE-2026-55379)
  * python-pillow: Pillow: Denial of Service via crafted GD 2.x image file (CVE-2026-55380)
  * python-pillow: Pillow: Denial of Service via crafted PCF font data (CVE-2026-54059)
  * python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files (CVE-2026-54060)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:39127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-pillow-2026-55380</id>
    <title>BIT-pillow-2026-55380 — Pillow GdImageFile decompression bomb protection bypass</title>
    <updated>2026-10-04T07:29:50.424381+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: pillow</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-pillow-2026-55380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-55380</id>
    <title>BREW-aider-CVE-2026-55380 — Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`</title>
    <updated>2026-10-04T07:29:50.424408+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aider</p>
<p>## Description</p>
<p>`PIL/GdImageFile.py` `GdImageFile._open()` reads image dimensions from the GD 2.x header and stores them in `self._size` without calling `Image._decompression_bomb_check()`. Because `GdImageFile` is **not registered with `Image.register_open()`**, it never passes through the standard `Image.open()` code path that enforces Pillow's decompression bomb guard. The plugin exposes its own entry point — `PIL.GdImageFile.open(fp)` — which directly instantiates the class, fully bypassing the documented protection.</p>
<p>**Vulnerable code (`PIL/GdImageFile.py` lines 50–61):**</p>
<p>```python
def _open(self) -&gt; None:
    s = self.fp.read(1037)
    if i16(s) not in [65534, 65535]:
        raise SyntaxError("Not a valid GD 2.x .gd file")
    self._mode = "P"
    self._size = i16(s, 2), i16(s, 4)   # ← unsigned 16-bit; max 65535 each
    # NO _decompression_bomb_check() call here ←
    ...
    self.tile = [ImageFile._Tile("raw", (0, 0) + self.size, 1037, "L")]
```</p>
<p>When `load()` is subsequently called on the returned image object:</p>
<p>```python
load() → load_prepare() → Image.core.new("P", (65535, 65535))
# ↑ C-level allocation of 4,294,836,225 bytes ≈ 4.3 GB — no Python bomb check precedes this
```</p>
<p>**Dimension arithmetic:**</p>
<p>| Field | Value |
|---|---|
| Maximum width from header | 65,535 (unsigned 16-bit) |
| Maximum height from header | 65,535 (unsigned 16-bit) |
| Maximum pixel count | 65,535 × 65,535 = **4,294,836,225** |
| `DecompressionBombError` threshold | 178,956,970 (2 × MA…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-55380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T07:29:50.424474+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333510</id>
    <title>EUVD-2026-333510</title>
    <updated>2026-10-04T07:29:50.424493+00:00</updated>
    <content>EUVD-2026-333510</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55380</id>
    <title>fkie_cve-2026-55380</title>
    <updated>2026-10-04T07:29:50.424506+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-phj9-mv4w-65pm</id>
    <title>GHSA-phj9-mv4w-65pm — Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`</title>
    <updated>2026-10-04T07:29:50.424528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pillow</p>
<p>## Description</p>
<p>`PIL/GdImageFile.py` `GdImageFile._open()` reads image dimensions from the GD 2.x header and stores them in `self._size` without calling `Image._decompression_bomb_check()`. Because `GdImageFile` is **not registered with `Image.register_open()`**, it never passes through the standard `Image.open()` code path that enforces Pillow's decompression bomb guard. The plugin exposes its own entry point — `PIL.GdImageFile.open(fp)` — which directly instantiates the class, fully bypassing the documented protection.</p>
<p>**Vulnerable code (`PIL/GdImageFile.py` lines 50–61):**</p>
<p>```python
def _open(self) -&gt; None:
    s = self.fp.read(1037)
    if i16(s) not in [65534, 65535]:
        raise SyntaxError("Not a valid GD 2.x .gd file")
    self._mode = "P"
    self._size = i16(s, 2), i16(s, 4)   # ← unsigned 16-bit; max 65535 each
    # NO _decompression_bomb_check() call here ←
    ...
    self.tile = [ImageFile._Tile("raw", (0, 0) + self.size, 1037, "L")]
```</p>
<p>When `load()` is subsequently called on the returned image object:</p>
<p>```python
load() → load_prepare() → Image.core.new("P", (65535, 65535))
# ↑ C-level allocation of 4,294,836,225 bytes ≈ 4.3 GB — no Python bomb check precedes this
```</p>
<p>**Dimension arithmetic:**</p>
<p>| Field | Value |
|---|---|
| Maximum width from header | 65,535 (unsigned 16-bit) |
| Maximum height from header | 65,535 (unsigned 16-bit) |
| Maximum pixel count | 65,535 × 65,535 = **4,294,836,225** |
| `DecompressionBombError` threshold | 178,956,970 (2 × MA…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-phj9-mv4w-65pm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3137</id>
    <title>OESA-2026-3137 — python-pillow security update</title>
    <updated>2026-10-04T07:29:50.424589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: python-pillow</p>
<p>Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)

Security Fix(es):</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.(CVE-2026-54059)</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(&amp;quot;1&amp;quot;, (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.(CVE-2026-54060)</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow&amp;apos;s documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.(CVE-2026-55379)</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimen…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3137"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11283-1</id>
    <title>openSUSE-SU-2026:11283-1 — python313-Pillow-12.3.0-2.1 on GA media</title>
    <updated>2026-10-04T07:29:50.424630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python313-Pillow-12.3.0-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11283-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2256</id>
    <title>PYSEC-2026-2256</title>
    <updated>2026-10-04T07:29:50.424651+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pillow</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:48759</id>
    <title>RHSA-2026:48759 — Red Hat Security Advisory: python-pillow security update</title>
    <updated>2026-10-04T07:29:50.424671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-pillow: Pillow: Denial of Service via crafted PCF font data python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:48759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:39127</id>
    <title>RLSA-2026:39127 — Important: python-pillow security update</title>
    <updated>2026-10-04T07:29:50.424692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: python-pillow</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* python-pillow: Pillow: Denial of Service via crafted BDF font file (CVE-2026-55379)</p>
<p>* python-pillow: Pillow: Denial of Service via crafted GD 2.x image file (CVE-2026-55380)</p>
<p>* python-pillow: Pillow: Denial of Service via crafted PCF font data (CVE-2026-54059)</p>
<p>* python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files (CVE-2026-54060)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:39127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22626-1</id>
    <title>SUSE-SU-2026:22626-1 — Security update for python-Pillow</title>
    <updated>2026-10-04T07:29:50.424720+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Pillow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22626-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55380</id>
    <title>UBUNTU-CVE-2026-55380</title>
    <updated>2026-10-04T07:29:50.424737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: pillow, Ubuntu:Pro:16.04:LTS: pillow, Ubuntu:Pro:18.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2, Ubuntu:22.04:LTS: pillow, Ubuntu:24.04:LTS: pillow, Ubuntu:26.04:LTS: pillow</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2301</id>
    <title>WID-SEC-W-2026-2301 — Red Hat Enterprise Linux (python-pillow): Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-04T07:29:50.424766+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux bzgl. python-pillow ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2301"/>
  </entry>
</feed>
