Executive brief
Pillow, a popular Python library for image processing, contains a vulnerability in its PDF parsing component. An attacker can provide a specially crafted PDF file that, when opened, consumes massive amounts of server memory (a 'decompression bomb'). This can lead to a denial-of-service by crashing the application or slowing down the entire server, affecting all users.
Technical details
The vulnerability exists in `PdfParser.PdfStream.decode()` within `PdfParser.py`. The component calls `zlib.decompress()` using the PDF stream's 'Length' field as the `bufsize` parameter. In Python's zlib implementation, `bufsize` is only an initial buffer hint and does not enforce a maximum limit on the decompressed output. An attacker can craft a PDF with a FlateDecode-compressed stream that expands significantly (e.g., 1 GB from < 1 MB), leading to uncontrolled resource consumption (CWE-400). This is reachable when an application uses `PdfParser` to read untrusted PDF files. The issue is fixed in Pillow version 12.3.0.
Affected products
- python-pillow Pillow >= 5.1.0, < 12.3.0
Timeline
- 2026-07-07: patched: Fix released in version 12.3.0
- 2026-07-14: advisory: NVD publication date
- 2026-07-20: disclosed: GitHub Advisory published