Junglewise Threat Intelligence

CVE-2026-42310: Pillow infinite loop in PDF trailer parsing

CVE-2026-42310 · Severity: medium · CVSS 5.5 · Published 2026-05-09

Technologies: pillow (PyPI). Vendors: PyPI.

Executive brief

Pillow is a widely used Python library for opening, manipulating, and saving many different image file formats. A vulnerability in its PDF parsing component allows a specially crafted PDF file to cause the application to stop responding. This results in 100% CPU usage and a total service outage for any application processing the malicious file, potentially impacting business operations and service availability.

Technical details

A Denial of Service (DoS) vulnerability exists in the PdfParser component of Pillow due to an infinite loop (CWE-835). The parser follows 'Prev' pointers in PDF trailers to read cross-reference sections; however, it fails to validate if a pointer references an offset that has already been processed. An attacker can provide a malicious PDF with a trailer cycle (where a trailer points to itself or forms a loop with others), causing the parser to hang indefinitely and consume maximum CPU resources. This issue is reachable if an application uses Pillow to process untrusted PDF files. The vulnerability is fixed in version 12.2.0 by tracking processed offsets and raising an error upon detecting a cycle.

Affected products

  • python-pillow Pillow >= 5.1.0, < 12.2.0

Timeline

  • 2026-03-31: patched: Fix merged into main branch
  • 2026-04-01: advisory: Release 12.2.0 published
  • 2026-05-09: disclosed: CVE published to NVD

References

Related threats