CVE-2026-40192: CWE-770: Allocation of Resources Without Limits or Throttling in python-pillow Pillow
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.
AI Analysis
Technical Summary
Pillow versions 10.3.0 through 12.1.1 do not limit the amount of GZIP-compressed data read when decoding FITS image files, making them vulnerable to decompression bomb attacks. A maliciously crafted FITS file can cause unbounded memory consumption, resulting in denial of service through out-of-memory crashes or severe performance degradation. The vulnerability is tracked as CVE-2026-40192 and is associated with CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-409 (Improper Handling of Highly Compressed Data). Red Hat's advisory confirms the issue but states that no mitigation or fix meeting their criteria is currently available. Users are advised to avoid opening FITS images if immediate upgrade is not possible. The vulnerability has a CVSS 3.1 base score of 7.5 (high severity) with network attack vector, no privileges required, and high impact on availability.
Potential Impact
Exploitation of this vulnerability can cause unbounded memory consumption on systems processing malicious FITS images, leading to denial of service conditions such as out-of-memory crashes or severe performance degradation. There is no impact on confidentiality or integrity. The vulnerability can be triggered remotely without authentication or user interaction.
Mitigation Recommendations
Currently, no official fix meeting Red Hat's criteria for ease of use, applicability, and stability is available. Users unable to upgrade immediately should mitigate risk by avoiding opening FITS image files. Monitor vendor advisories for updates and apply patches once released.
CVE-2026-40192: CWE-770: Allocation of Resources Without Limits or Throttling in python-pillow Pillow
Description
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.
CVSS v4.0
Score 8.7high
Affected software
python-pillow
Pillow
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Pillow versions 10.3.0 through 12.1.1 do not limit the amount of GZIP-compressed data read when decoding FITS image files, making them vulnerable to decompression bomb attacks. A maliciously crafted FITS file can cause unbounded memory consumption, resulting in denial of service through out-of-memory crashes or severe performance degradation. The vulnerability is tracked as CVE-2026-40192 and is associated with CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-409 (Improper Handling of Highly Compressed Data). Red Hat's advisory confirms the issue but states that no mitigation or fix meeting their criteria is currently available. Users are advised to avoid opening FITS images if immediate upgrade is not possible. The vulnerability has a CVSS 3.1 base score of 7.5 (high severity) with network attack vector, no privileges required, and high impact on availability.
Potential Impact
Exploitation of this vulnerability can cause unbounded memory consumption on systems processing malicious FITS images, leading to denial of service conditions such as out-of-memory crashes or severe performance degradation. There is no impact on confidentiality or integrity. The vulnerability can be triggered remotely without authentication or user interaction.
Mitigation Recommendations
Currently, no official fix meeting Red Hat's criteria for ease of use, applicability, and stability is available. Users unable to upgrade immediately should mitigate risk by avoiding opening FITS image files. Monitor vendor advisories for updates and apply patches once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-09T20:59:17.620Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-40192","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:24761","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27076","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:24762","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16008","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16030","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16009","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:16174","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:24866","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17611","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17609","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:24977","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19712","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22629","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21017","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:24853","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19375","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22465","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22840","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23361","vendor":"Red Hat"}]
Threat ID: 69e01c6582d89c981fa691af
Added to database: 04/15/2026, 23:16:53 UTC
Last enriched: 08/14/2026, 14:43:02 UTC
Last updated: 09/14/2026, 22:11:27 UTC
Views: 187
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.