VDB
KO
HIGH 7.5

PYSEC-2026-2253

Quick fix

PYSEC-2026-2253 — pillow: upgrade to the fixed version with the command below.

pip install --upgrade 'pillow>=12.3.0'

Details

Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pillow
Introduced in: 0 Fixed in: 12.3.0
Fix pip install --upgrade 'pillow>=12.3.0'

References