Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.
Metrics
Affected Vendors & Products
References
History
Sat, 09 May 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python-pillow
Python-pillow pillow |
|
| Vendors & Products |
Python-pillow
Python-pillow pillow |
Sat, 09 May 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0. | |
| Title | Pillow: PDF Parsing Trailer Infinite Loop (DoS) | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-05-09T04:10:48.395Z
Updated: 2026-05-09T04:10:48.395Z
Reserved: 2026-04-26T12:37:18.169Z
Link: CVE-2026-42310
No data.
Status : Received
Published: 2026-05-09T06:16:10.273
Modified: 2026-05-09T06:16:10.273
Link: CVE-2026-42310
No data.