<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:44:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05627</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05627</link>
      <description>bdu:2026-05627</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05627</guid>
    </item>
    <item>
      <title>BIT-pillow-2026-40192 — Pillow is vulnerable to a FITS GZIP decompression bomb</title>
      <link>https://cve.radiocsirt.org/vuln/bit-pillow-2026-40192</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-pillow-2026-40192</guid>
    </item>
    <item>
      <title>BREW-aider-CVE-2026-40192 — FITS GZIP decompression bomb in Pillow</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-40192</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;### Impact
Pillow did not limit the amount of GZIP-compressed data read when decoding a FITS image, making it vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation).&lt;/p&gt;
&lt;p&gt;### Patches
The amount of data read is now limited to the necessary amount.
Fixed in Pillow 12.2.0 (PR #9521).&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid Pillow &amp;gt;= 10.3.0, &amp;lt; 12.2.0
Only open [specific image formats](https://pillow.readthedocs.io/en/stable/releasenotes/8.0.0.html#image-open-add-formats-parameter), excluding FITS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;### Impact
Pillow did not limit the amount of GZIP-compressed data read when decoding a FITS image, making it vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation).&lt;/p&gt;
&lt;p&gt;### Patches
The amount of data read is now limited to the necessary amount.
Fixed in Pillow 12.2.0 (PR #9521).&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid Pillow &amp;gt;= 10.3.0, &amp;lt; 12.2.0
Only open [specific image formats](https://pillow.readthedocs.io/en/stable/releasenotes/8.0.0.html#image-open-add-formats-parameter), excluding FITS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-40192</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0556 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556</link>
      <description>certfr-2026-avi-0556</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-EC11110 — undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier pa…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ec11110</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-superset&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-superset package. undici&amp;#39;s retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response&amp;#39;s status and headers. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-superset&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-superset package. undici&amp;#39;s retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response&amp;#39;s status and headers. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ec11110</guid>
    </item>
    <item>
      <title>EUVD-2026-366069</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366069</link>
      <description>EUVD-2026-366069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366069</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40192</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40192</link>
      <description>&lt;p&gt;Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40192</guid>
    </item>
    <item>
      <title>GHSA-whj4-6x5x-4v2j — FITS GZIP decompression bomb in Pillow</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-whj4-6x5x-4v2j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;### Impact
Pillow did not limit the amount of GZIP-compressed data read when decoding a FITS image, making it vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation).&lt;/p&gt;
&lt;p&gt;### Patches
The amount of data read is now limited to the necessary amount.
Fixed in Pillow 12.2.0 (PR #9521).&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid Pillow &amp;gt;= 10.3.0, &amp;lt; 12.2.0
Only open [specific image formats](https://pillow.readthedocs.io/en/stable/releasenotes/8.0.0.html#image-open-add-formats-parameter), excluding FITS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;### Impact
Pillow did not limit the amount of GZIP-compressed data read when decoding a FITS image, making it vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation).&lt;/p&gt;
&lt;p&gt;### Patches
The amount of data read is now limited to the necessary amount.
Fixed in Pillow 12.2.0 (PR #9521).&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid Pillow &amp;gt;= 10.3.0, &amp;lt; 12.2.0
Only open [specific image formats](https://pillow.readthedocs.io/en/stable/releasenotes/8.0.0.html#image-open-add-formats-parameter), excluding FITS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-whj4-6x5x-4v2j</guid>
    </item>
    <item>
      <title>OESA-2026-2064 — python-pillow security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2064</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-pillow&lt;/p&gt;
&lt;p&gt;Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.(CVE-2026-40192)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-pillow&lt;/p&gt;
&lt;p&gt;Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.(CVE-2026-40192)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2064</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10575-1 — python311-Pillow-12.2.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10575-1</link>
      <description>&lt;p&gt;python311-Pillow-12.2.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-Pillow-12.2.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10575-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2250</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2250</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2250</guid>
    </item>
    <item>
      <title>RHSA-2026:16008 — Red Hat Security Advisory: Red Hat AI Inference Server Model Optimization Tools 3.3.3 (CUDA)</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:16008</link>
      <description>&lt;p&gt;libxslt: Processing web content may disclose sensitive information gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing python: Python: Command-line option injection in webbrowser.open() via crafted URLs libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image giflib: Giflib: Double-free vulnerability leading to memory corruption vim: Vim: Arbitrary code execution via &amp;#39;helpfile&amp;#39; option processing nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination openexr: OpenEXR: Arbitrary code execution via integer overflow in EXR file processing vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin vim: Vim: Denial of service and information disclosure via crafted swap file vim: Vim: Arbitrary code execution via command injection in glob() function Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing Pillow: Pillow: Denial of Service via integer overflow in font processing Pillow: Pillow: Den…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libxslt: Processing web content may disclose sensitive information gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing python: Python: Command-line option injection in webbrowser.open() via crafted URLs libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image giflib: Giflib: Double-free vulnerability leading to memory corruption vim: Vim: Arbitrary code execution via &amp;#39;helpfile&amp;#39; option processing nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination openexr: OpenEXR: Arbitrary code execution via integer overflow in EXR file processing vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin vim: Vim: Denial of service and information disclosure via crafted swap file vim: Vim: Arbitrary code execution via command injection in glob() function Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing Pillow: Pillow: Denial of Service via integer overflow in font processing Pillow: Pillow: Den…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:16008</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21382-1 — Security update for python-Pillow</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21382-1</link>
      <description>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21382-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-40192</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40192</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: pillow, Ubuntu:26.04:LTS: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.10: pillow, Ubuntu:26.04:LTS: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40192</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2166 — Red Hat Satellite (foreman, python-pillow, go): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2166</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Satellite ausnutzen, um sich erweiterte Rechte, einschließlich Administratorrechte, zu verschaffen, die Authentifizierung zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Satellite ausnutzen, um sich erweiterte Rechte, einschließlich Administratorrechte, zu verschaffen, die Authentifizierung zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2166</guid>
    </item>
  </channel>
</rss>
