CVE-2026-42310

EUVD-2026-28902
Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Affected Products (NVD)
VendorProductVersion
pythonpillow
4.2.0 ≤
𝑥
< 12.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pillow
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
12.2.0-1
fixed
sid
12.2.0-1
fixed
trixie
vulnerable
trixie (security)
11.1.0-5+deb13u3
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
python311-Pillow
suse enterprise desktop 15 SP7
9.5.0-150400.5.20.1
fixed
suse enterprise sap 15 SP4
9.5.0-150400.5.20.1
fixed
suse enterprise sap 15 SP5
9.5.0-150400.5.20.1
fixed
suse enterprise sap 15 SP6
9.5.0-150400.5.20.1
fixed
suse enterprise sap 15 SP7
9.5.0-150400.5.20.1
fixed
suse enterprise server 15 SP4
9.5.0-150400.5.20.1
fixed
suse enterprise server 15 SP5
9.5.0-150400.5.20.1
fixed
suse enterprise server 15 SP6
9.5.0-150400.5.20.1
fixed
suse enterprise server 15 SP7
9.5.0-150400.5.20.1
fixed
python311-Pillow-tk
suse enterprise desktop 15 SP7
9.5.0-150400.5.20.1
fixed
suse enterprise sap 15 SP4
9.5.0-150400.5.20.1
fixed
suse enterprise sap 15 SP5
9.5.0-150400.5.20.1
fixed
suse enterprise sap 15 SP6
9.5.0-150400.5.20.1
fixed
suse enterprise sap 15 SP7
9.5.0-150400.5.20.1
fixed
suse enterprise server 15 SP4
9.5.0-150400.5.20.1
fixed
suse enterprise server 15 SP5
9.5.0-150400.5.20.1
fixed
suse enterprise server 15 SP6
9.5.0-150400.5.20.1
fixed
suse enterprise server 15 SP7
9.5.0-150400.5.20.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python-pillow-debuginfo
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python-pillow-debugsource
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python3-pillow
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python3-pillow-debuginfo
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python3-pillow-devel
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python3-pillow-tk
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python3-pillow-tk-debuginfo
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed