PT-2026-37199 · Pypi+3 · Pillow+3

·

CVE-2026-42310

·

Published

2026-05-04

·

Updated

2026-07-13

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pillow versions 4.2.0 through 12.1.x
Description A flaw in the PdfParser allows an attacker to supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This occurs because the parser follows Prev pointers in PDF trailers to read cross-reference sections; if a pointer references an offset already processed, either by pointing to itself or forming a cycle, the parser enters an infinite loop.
Recommendations Update to version 12.2.0.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10817
BIT-PILLOW-2026-42310
CLEANSTART-2026-EN66750
CLEANSTART-2026-FG72002
CLEANSTART-2026-RF67070
CVE-2026-42310
ECHO-55B6-3B95-3506
GHSA-R73J-PQJ5-W3X7
OPENSUSE-SU-2026:20831-1
PYSEC-2026-2874
SUSE-SU-2026:1842-1
SUSE-SU-2026:21861-1
SUSE-SU-2026:2234-1
USN-8399-1

Affected Products

Linuxmint
Pillow
Red Os
Ubuntu