CVE-2026-40192

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.
References
Link Resource
https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628 Patch
https://github.com/python-pillow/Pillow/pull/9521 Issue Tracking Patch
https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j Mitigation Patch Vendor Advisory
https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb Release Notes
https://access.redhat.com/errata/RHSA-2026:16008
https://access.redhat.com/errata/RHSA-2026:16009
https://access.redhat.com/errata/RHSA-2026:16030
https://access.redhat.com/errata/RHSA-2026:16174
https://access.redhat.com/errata/RHSA-2026:17609
https://access.redhat.com/errata/RHSA-2026:17611
https://access.redhat.com/errata/RHSA-2026:19375
https://access.redhat.com/errata/RHSA-2026:19712
https://access.redhat.com/errata/RHSA-2026:21017
https://access.redhat.com/errata/RHSA-2026:22465
https://access.redhat.com/errata/RHSA-2026:22629
https://access.redhat.com/errata/RHSA-2026:22840
https://access.redhat.com/errata/RHSA-2026:23361
https://access.redhat.com/errata/RHSA-2026:24761
https://access.redhat.com/errata/RHSA-2026:24762
https://access.redhat.com/errata/RHSA-2026:24853
https://access.redhat.com/errata/RHSA-2026:24866
https://access.redhat.com/errata/RHSA-2026:24977
https://access.redhat.com/errata/RHSA-2026:27076
https://access.redhat.com/errata/RHSA-2026:34365
https://access.redhat.com/errata/RHSA-2026:34366
https://access.redhat.com/errata/RHSA-2026:34368
https://access.redhat.com/errata/RHSA-2026:37275
https://access.redhat.com/security/cve/CVE-2026-40192
https://bugzilla.redhat.com/show_bug.cgi?id=2458856
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json
Configurations

Configuration 1 (hide)

cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*

History

10 Jul 2026, 12:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:37275 -

02 Jul 2026, 12:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:34365 -
  • () https://access.redhat.com/errata/RHSA-2026:34366 -
  • () https://access.redhat.com/errata/RHSA-2026:34368 -

30 Jun 2026, 03:19

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:16008 -
  • () https://access.redhat.com/errata/RHSA-2026:16009 -
  • () https://access.redhat.com/errata/RHSA-2026:16030 -
  • () https://access.redhat.com/errata/RHSA-2026:16174 -
  • () https://access.redhat.com/errata/RHSA-2026:17609 -
  • () https://access.redhat.com/errata/RHSA-2026:17611 -
  • () https://access.redhat.com/errata/RHSA-2026:19375 -
  • () https://access.redhat.com/errata/RHSA-2026:19712 -
  • () https://access.redhat.com/errata/RHSA-2026:21017 -
  • () https://access.redhat.com/errata/RHSA-2026:22465 -
  • () https://access.redhat.com/errata/RHSA-2026:22629 -
  • () https://access.redhat.com/errata/RHSA-2026:22840 -
  • () https://access.redhat.com/errata/RHSA-2026:23361 -
  • () https://access.redhat.com/errata/RHSA-2026:24761 -
  • () https://access.redhat.com/errata/RHSA-2026:24762 -
  • () https://access.redhat.com/errata/RHSA-2026:24853 -
  • () https://access.redhat.com/errata/RHSA-2026:24866 -
  • () https://access.redhat.com/errata/RHSA-2026:24977 -
  • () https://access.redhat.com/errata/RHSA-2026:27076 -
  • () https://access.redhat.com/security/cve/CVE-2026-40192 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2458856 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json -
CWE CWE-409

22 Apr 2026, 20:08

Type Values Removed Values Added
References () https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628 - () https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628 - Patch
References () https://github.com/python-pillow/Pillow/pull/9521 - () https://github.com/python-pillow/Pillow/pull/9521 - Issue Tracking, Patch
References () https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j - () https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j - Mitigation, Patch, Vendor Advisory
References () https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb - () https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb - Release Notes
CPE cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Python
Python pillow

15 Apr 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-15 23:16

Updated : 2026-07-20 12:19


NVD link : CVE-2026-40192

Mitre link : CVE-2026-40192

CVE.ORG link : CVE-2026-40192


JSON object : View

Products Affected

python

  • pillow
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling

CWE-409

Improper Handling of Highly Compressed Data (Data Amplification)