Pillow 10.3.012.1.1 GZIP decompress bomb in FITS decoder (CVE202640192)
CVE-2026-40192 Published on April 15, 2026
Pillow is vulnerable to a FITS GZIP decompression bomb
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.
Vulnerability Analysis
CVE-2026-40192 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Types
Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
What is a Resource Exhaustion Vulnerability?
The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVE-2026-40192 has been classified to as a Resource Exhaustion vulnerability or weakness.
What is a Data Amplification Vulnerability?
The software does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output. An example of data amplification is a "decompression bomb," a small ZIP file that can produce a large amount of data when it is decompressed.
CVE-2026-40192 has been classified to as a Data Amplification vulnerability or weakness.
Products Associated with CVE-2026-40192
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-40192 are published in these products:
Affected Versions
python-pillow Pillow:- Version >= 10.3.0, < 12.2.0 is affected.
- Version 0:12.2.0-1.el8ap and below * is unaffected.
- Version 0:12.2.0-1.el9ap and below * is unaffected.
- Version 0:12.2.0-1.el9ap and below * is unaffected.
- Version 0:12.2.0-1.el8pc and below * is unaffected.
- Version 0:12.2.0-1.el9pc and below * is unaffected.
- Version 0:12.2.0-1.el9pc and below * is unaffected.
- Version 0:12.2.0-1.el9pc and below * is unaffected.
- Version 0:12.2.0-1.el9pc and below * is unaffected.
- Version 1778244559 and below * is unaffected.
- Version 1778244531 and below * is unaffected.
- Version 1778274666 and below * is unaffected.
- Version 1778244546 and below * is unaffected.
- Version 1779761061 and below * is unaffected.
- Version 1780102732 and below * is unaffected.
- Version 1778690639 and below * is unaffected.
- Version 1778677633 and below * is unaffected.
- Version 1778677632 and below * is unaffected.
- Version 1778677745 and below * is unaffected.
- Version 1778666122 and below * is unaffected.
- Version 1778677632 and below * is unaffected.
- Version 1778666124 and below * is unaffected.
- Version 1780388133 and below * is unaffected.
- Version 1778677779 and below * is unaffected.
- Version 1778677692 and below * is unaffected.
- Version 1778262893 and below * is unaffected.
- Version 1778677701 and below * is unaffected.
- Version 1778677741 and below * is unaffected.
- Version 1778677767 and below * is unaffected.
- Version 1779123334 and below * is unaffected.
- Version 1778263128 and below * is unaffected.
- Version 1778782933 and below * is unaffected.
- Version 1778677718 and below * is unaffected.
- Version 1778677716 and below * is unaffected.
- Version 1778263054 and below * is unaffected.
- Version 1778677734 and below * is unaffected.
- Version 1778677667 and below * is unaffected.
- Version 1778677717 and below * is unaffected.
- Version 1778677722 and below * is unaffected.
- Version 1782472374 and below * is unaffected.
- Version 1782471606 and below * is unaffected.
- Version 1779822261 and below * is unaffected.
- Version 1779811412 and below * is unaffected.
- Version 1779689392 and below * is unaffected.
- Version 1780891395 and below * is unaffected.
- Version 1779204086 and below * is unaffected.
- Version 1779922205 and below * is unaffected.
- Version 1779811473 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.