Infinite loop in Pillow - CVE-2026-59203
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the EPS parser in PIL/EpsImagePlugin.py when parsing a crafted EPS %%BeginBinary directive during Image.open(). A remote attacker can supply a specially crafted EPS file with a negative byte count to cause a denial of service.
The issue is triggered during Image.open(), does not require calling Image.load(), and does not require Ghostscript execution.
Affected software
Anolis OS
python3-pillow
python3-pillow-devel
python3-pillow-qt
python3-pillow-tk
python3-pillow-doc
How to mitigate CVE-2026-59203
python3-pillow - update to 12.2.0-3
python3-pillow-devel - update to 12.2.0-3
python3-pillow-qt - update to 12.2.0-3
python3-pillow-tk - update to 12.2.0-3
python3-pillow-doc - update to 12.2.0-3