VDB
Sign up
MEDIUM5.5

PYSEC-2026-2874

Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

Quick fix

PYSEC-2026-2874 — pillow: upgrade to the fixed version with the command below.

pip install --upgrade 'pillow>=12.2.0'

Details

### Impact An attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive.

### Patches Patched version: 12.2.0.

PdfParser (introduced in Pillow 4.2.0) follows Prev pointers in PDF trailers to read cross-reference sections. If a trailer's Prev pointer references an offset that has already been processed — either pointing to itself or forming a longer cycle — the parser enters an infinite loop. Pillow now tracks previously processed trailer offsets and raises an error if a cycle is detected.

### Workarounds Use any version but the affected versions: >= 4.2.0, < 12.2.0

### Resources - Fix: https://github.com/python-pillow/Pillow/pull/9519

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pillow
Introduced in: 4.2.0Fixed in: 12.2.0
Fixpip install --upgrade 'pillow>=12.2.0'

References