CVE-2026-59203
גבוהה 7.5
תיאור (מקור, אנגלית)
Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to the same directive and parse it repeatedly in an infinite loop. This issue is fixed in version 12.3.0.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-14/8/2026
- CWE
- CWE-835
מוצרים מושפעים
python: pillow
קישורים
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-pg7v-jwj7-p798 ExploitVendor Advisory
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-pg7v-jwj7-p798 ExploitVendor Advisory
- https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd… Patch
- https://github.com/python-pillow/Pillow/pull/9708 Issue TrackingPatch
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0 Release Notes