Executive brief
Pillow, a popular Python library for image processing, is vulnerable to a 'decompression bomb' attack when loading PCF font files. An attacker can provide a specially crafted, small font file that causes the system to attempt to allocate massive amounts of memory (over 1GB). This can lead to a denial-of-service condition, crashing the application or the server it is running on.
Technical details
The vulnerability exists in `PIL/PcfFontFile.py` within the `_load_bitmaps()` function. It reads glyph dimensions directly from the PCF `METRICS` section and passes them to `Image.frombytes()` without performing the standard `_decompression_bomb_check()`. Because these dimensions are derived from unsigned 16-bit values, an attacker can specify dimensions that result in over 8.5 billion pixels. This triggers a large C-heap allocation in `Image.new()` before any data validation occurs. The attack can be 'transient' (using a tiny file to cause a memory spike) or 'persistent' (providing enough data to fill the buffer). The issue is fixed in Pillow version 12.3.0.
Affected products
- python-pillow Pillow < 12.3.0
Timeline
- 2026-06-07: other: Confirmed unpatched on main branch
- 2026-07-03: disclosed
- 2026-07-06: advisory: NVD publication
- 2026-07-20: advisory: GitHub Advisory published
References
- https://api.github.com/users/x-forwarded-sudo
- https://github.com/x-forwarded-sudo
- https://api.github.com/users/x-forwarded-sudo/gists%7B/gist_id%7D
- https://api.github.com/users/x-forwarded-sudo/repos
- https://avatars.githubusercontent.com/u/223256873?v=4
- https://api.github.com/users/x-forwarded-sudo/events%7B/privacy%7D