Executive brief
Pillow, a popular Python library for image processing, contains a vulnerability in how it handles GD 2.x image files. An attacker can provide a specially crafted, very small image file (about 1KB) that forces the library to attempt to allocate over 4GB of memory. This can lead to a denial-of-service condition where the application crashes or becomes unresponsive due to memory exhaustion.
Technical details
The GdImageFile plugin in Pillow does not call Image._decompression_bomb_check() during its _open() method. Because this plugin is not registered with the standard Image.register_open() system and is instead accessed via its own entry point (PIL.GdImageFile.open), it bypasses the library's global protection against decompression bombs. An attacker can craft a GD 2.x header (1,037 bytes) specifying maximum dimensions (65535x65535), which triggers a ~4.3 GB C-level heap allocation when load() is called. This exceeds the default DecompressionBombError threshold by approximately 24 times. The issue is fixed in Pillow version 12.3.0.
Affected products
- python-pillow Pillow < 12.3.0
Timeline
- 2026-06-08: disclosed: Confirmed unpatched on main branch
- 2026-07-03: advisory: GitHub Advisory published
- 2026-07-06: kev added: NVD publication date
- 2026-07-20: patched: Updated in GitHub Advisory Database with patch version 12.3.0
References
- https://api.github.com/users/x-forwarded-sudo
- https://github.com/x-forwarded-sudo
- https://api.github.com/users/x-forwarded-sudo/gists%7B/gist_id%7D
- https://api.github.com/users/x-forwarded-sudo/repos
- https://avatars.githubusercontent.com/u/223256873?v=4
- https://api.github.com/users/x-forwarded-sudo/events%7B/privacy%7D