CVE-2026-42308

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*

History

12 May 2026, 17:57

Type Values Removed Values Added
References () https://github.com/python-pillow/Pillow/releases/tag/12.2.0 - () https://github.com/python-pillow/Pillow/releases/tag/12.2.0 - Product, Release Notes
References () https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j - () https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j - Vendor Advisory
CPE cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
First Time Python
Python pillow
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

09 May 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-09 06:16

Updated : 2026-05-12 17:57


NVD link : CVE-2026-42308

Mitre link : CVE-2026-42308

CVE.ORG link : CVE-2026-42308


JSON object : View

Products Affected

python

  • pillow
CWE
CWE-190

Integer Overflow or Wraparound