Resource exhaustion in Pillow - CVE-2026-40192

 

Resource exhaustion in Pillow - CVE-2026-40192

Published: April 11, 2026


Vulnerability identifier: #VU125817
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40192
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the FITS image decoder when parsing a specially crafted GZIP-compressed FITS file. A remote attacker can supply a specially crafted FITS file to cause a denial of service.

The issue can result in unbounded memory consumption, leading to an out-of-memory crash or severe performance degradation.


Affected software

Pillow
Debian Linux
Anolis OS
openEuler
Fedora
Fusion Content-Aware Storage
Data Cataloging
IBM Fusion HCI
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
python3-pillow-tk
python3-pillow-qt
python3-pillow-help
python-pillow
python-pillow-debuginfo
python-pillow-debugsource
python3-pillow
python3-pillow-devel
python3-pillow-doc
pillow (Debian package)

How to mitigate CVE-2026-40192

Install security update from vendor's website.

Pillow - update to 12.2.0
Fusion Content-Aware Storage - update to 1.1.5
IBM Fusion HCI - update to 2.13.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
Data Cataloging - update to 2.5.3
python3-pillow-tk - update to 10.3.0-3
python3-pillow-qt - update to 10.3.0-3
python3-pillow-help - update to 10.3.0-3
python-pillow - update to 10.3.0-3
python-pillow-debuginfo - update to 10.3.0-3
python-pillow-debugsource - update to 10.3.0-3
python3-pillow - update to 10.3.0-3
python3-pillow-devel - update to 10.3.0-3
python3-pillow - update to 10.3.0-3
python3-pillow-devel - update to 10.3.0-3
python3-pillow-qt - update to 10.3.0-3
python3-pillow-tk - update to 10.3.0-3
python3-pillow-doc - update to 10.3.0-3
pillow (Debian package) - update to 11.1.0-5+deb13u2
python-pillow - addressed in versions 11.3.0-8.fc43, 12.2.0-1.fc44

External References

Related Security Bulletins