Infinite loop in Pillow - CVE-2026-42310

 

Infinite loop in Pillow - CVE-2026-42310

Published: April 23, 2026


Vulnerability identifier: #VU127176
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-42310
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Pillow
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
openEuler
Anolis OS
python3-Pillow-tk-debuginfo
python3-Pillow-debuginfo
python-Pillow-debugsource
python3-Pillow
python-Pillow-debuginfo
python3-Pillow-tk
python3-pillow-qt
python3-pillow-help
python3-pillow-tk
python3-pillow-devel
python3-pillow
python-pillow-debugsource
python-pillow-debuginfo
python-pillow
python3-pillow-doc

Detailed vulnerability description

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an infinite loop in PdfParser when parsing a malicious PDF trailer with cyclic Prev pointers. A remote attacker can supply a specially crafted PDF file to cause a denial of service.

The issue can cause the process to hang indefinitely, consume 100% CPU, and make the application unresponsive.


How to mitigate CVE-2026-42310

Install security update from vendor's website.

Sources