Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.
References
| Link | Resource |
|---|---|
| https://github.com/python-pillow/Pillow/releases/tag/12.2.0 | Product Release Notes |
| https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j | Vendor Advisory |
Configurations
History
12 May 2026, 17:57
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/python-pillow/Pillow/releases/tag/12.2.0 - Product, Release Notes | |
| References | () https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j - Vendor Advisory | |
| CPE | cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:* | |
| First Time |
Python
Python pillow |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
09 May 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-09 06:16
Updated : 2026-05-12 17:57
NVD link : CVE-2026-42308
Mitre link : CVE-2026-42308
CVE.ORG link : CVE-2026-42308
JSON object : View
Products Affected
python
- pillow
CWE
CWE-190
Integer Overflow or Wraparound
