Executive brief
Pillow, a popular Python library for image processing, is vulnerable to a denial-of-service attack when processing specially crafted font files. An attacker can provide a malicious font file that, when loaded or converted, forces the library to allocate an enormous amount of memory, potentially crashing the application or the entire server. This affects services that allow users to upload or preview fonts, such as web-based font renderers or automated document processing pipelines.
Technical details
A decompression bomb vulnerability exists in Pillow's `FontFile.compile()` method, which is used by `BdfFontFile` and `PcfFontFile`. The `compile()` method assembles glyphs into a combined bitmap using `Image.new()` without performing the standard `_decompression_bomb_check()`. Because these font formats are not registered via `Image.open()`, they bypass Pillow's global pixel limit guards. An attacker can provide a crafted BDF or PCF file where individual glyphs are below the warning threshold, but their cumulative size in the final bitmap exceeds the `DecompressionBombError` threshold (e.g., reaching 13.4 billion pixels or ~1.6 GB of memory). This can be triggered via `to_imagefont()` or `save()` calls. The issue is fixed in version 12.3.0.
Affected products
- python-pillow Pillow < 12.3.0
Timeline
- 2026-06-08: disclosed: Confirmed unpatched on main branch
- 2026-07-03: advisory: GitHub Advisory published
- 2026-07-06: kev added: NVD published date
- 2026-07-20: patched: Advisory updated with patch information