VDB
KO
HIGH 7.5

PYSEC-2026-2255

Quick fix

PYSEC-2026-2255 — pillow: upgrade to the fixed version with the command below.

pip install --upgrade 'pillow>=12.3.0'

Details

Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pillow
Introduced in: 0 Fixed in: 12.3.0
Fix pip install --upgrade 'pillow>=12.3.0'

References