CVE-2026-42308

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) Pillow es una biblioteca de procesamiento de imágenes de Python. Antes de la versión 12.2.0, si una fuente avanza para cada glifo una cantidad excesivamente grande, cuando Pillow rastrea la posición actual, esto puede provocar un desbordamiento de entero. Este problema ha sido parcheado en la versión 12.2.0.

12 May 2026, 17:57

Type Values Removed Values Added
References () https://github.com/python-pillow/Pillow/releases/tag/12.2.0 - () https://github.com/python-pillow/Pillow/releases/tag/12.2.0 - Product, Release Notes
References () https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j - () https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j - Vendor Advisory
CPE cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
First Time Python
Python pillow
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

09 May 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-09 06:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-42308

Mitre link : CVE-2026-42308

CVE.ORG link : CVE-2026-42308


JSON object : View

Products Affected

python

  • pillow
CWE
CWE-190

Integer Overflow or Wraparound