chore(deps): Update dependency Pillow to >=12.3.0,<14.0 [SECURITY] - #1084
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): Update dependency Pillow to >=12.3.0,<14.0 [SECURITY]#1084renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
>=12.2.0,<14.0→>=12.3.0,<14.0>=12.2.0→>=12.3.0Pillow
BdfFontFile:Image.new()called without_decompression_bomb_check()— bomb protection bypass via font loadingBIT-pillow-2026-55379 / CVE-2026-55379 / GHSA-45hq-cxwh-f6vc / PYSEC-2026-2255
More information
Details
Summary
PIL/BdfFontFile.pybdf_char()(lines 84–88) reads theBBX width heightfield from a BDF font file and passes the dimensions directly toImage.new()without callingImage._decompression_bomb_check(). This completely bypasses Pillow's documented decompression bomb protection.Image.open()enforcesMAX_IMAGE_PIXELS = 89,478,485and raisesDecompressionBombErrorfor images exceeding2 × MAX = 178,956,970pixels. The BDF font loading path callsImage.new()directly, which only calls_check_size()(validates>= 0) — no pixel count limit.Vulnerable code (
PIL/BdfFontFile.pylines 84–88):Attack trigger: A BDF glyph with
BBX 20000 20000and an emptyBITMAPsection causesImage.frombytes()to raiseValueError, thenImage.new("1", (20000, 20000))allocates 50 MB of C-heap silently. Image.open() would raiseDecompressionBombErrorfor the same dimensions.Steps to reproduce
Minimal malicious BDF file (270 bytes):
Proof of Concept script:
Expected output:
Amplified attack (multiple glyphs):
A BDF file defining 256 glyphs each at
BBX 8000 8000causes256 × 7.6 MB = ~1.95 GBtotal C-heap allocation — all silently, bypassing documented bomb protection.Impact
ImageFont.load("user.bdf"),BdfFontFile(fp)) is affectedself.glyph[ch]for the lifetime of the font object — memory is NOT freed until the font is garbage collectedSeverity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
BIT-pillow-2026-55798 / CVE-2026-55798 / GHSA-4x4j-2g7c-83w6 / PYSEC-2026-2257
More information
Details
1. Summary
WindowsViewer.get_command()constructs acmd.exeshell command by directly embedding afile path into an f-string without escaping. The result is passed to
subprocess.Popen(..., shell=True). Shell metacharacters in the file path — mostimportantly a double-quote (
") that breaks out of the wrapping, followed by&— allowinjection of arbitrary
cmd.execommands.The macOS equivalent (
MacViewer) correctly appliesshlex.quote()to the same parameter.The Linux equivalent (
UnixViewer) does likewise. Windows is the only platform missing thisprotection, despite
shlex.quotebeing already imported on line 21 ofImageShow.py.2. Vulnerable Code
File:
src/PIL/ImageShow.py, lines 133–150Contrast with macOS — SAFE (line 164–168):
Cross-platform summary:
shlex.quote()?shell=True?MacViewerUnixViewerWindowsViewershlex.quoteis imported on line 21. Its omission from the Windows path is a clearoversight, not a deliberate design choice.
3. Proof of Concept
A full working PoC is at
poc_pillow_injection.py. Key parts:Part A — Injection string construction (static, no execution):
Part B — Live execution via
os.system()(verified on Windows 11, Pillow 12.1.1):Severity
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Pillow:
FontFile.compile():Image.new()called without_decompression_bomb_check()BIT-pillow-2026-54060 / CVE-2026-54060 / GHSA-5x94-69rx-g8h2 / PYSEC-2026-2254
More information
Details
Description
PIL/FontFile.pyFontFile.compile()assembles per-glyph images into a single combined bitmap usingImage.new("1", (xsize, ysize))without callingImage._decompression_bomb_check(). This is the base-class method shared by bothBdfFontFileandPcfFontFile, and it is triggered whenever a loaded font is converted to anImageFontor saved.Neither
BdfFontFile.BdfFontFile(fp)norPcfFontFile.PcfFontFile(fp)is registered withImage.register_open(), so Pillow's standard decompression bomb guard never fires for font objects. The compile step is the final opportunity to check the combined allocation — and it has no check.Vulnerable code (
PIL/FontFile.pylines ~64–92):"Slow accumulation" attack — per-glyph dimensions stay BELOW warning threshold:
With PCF-maximum glyph height (65,535):
Steps to reproduce
Proof of Concept script:
Expected output:
Verified live on Pillow 12.2.0 — compile() succeeds with no exception.
Real-world trigger using BDF font file:
Attack scenarios:
BdfFontFile(upload).to_imagefont())to_imagefont()Impact
compile()creates a combined bitmap whose pixel count scales asWIDTH × lines × max_glyph_heightwith no upper bound check. With max PCF glyph height (65,535) and 256 glyphs, the combined allocation is ~1.6 GB. With BDF (text-format, unbounded height), the allocation is limited only by system memory.Affected call paths:
BdfFontFile.BdfFontFile(fp).to_imagefont()→FontFile.compile()BdfFontFile.BdfFontFile(fp).save(filename)→FontFile.compile()PcfFontFile.PcfFontFile(fp).to_imagefont()→FontFile.compile()PcfFontFile.PcfFontFile(fp).save(filename)→FontFile.compile()Neither
BdfFontFilenorPcfFontFileis loaded viaImage.open(), so the standard decompression bomb guard is entirely absent from the font loading code path.compile()is the only point where the combined allocation size is known, and it has no check.Confirmed unpatched on
python-pillow/Pillowmainbranch as of 2026-06-08.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
BIT-pillow-2026-54058 / CVE-2026-54058 / GHSA-62p4-gmf7-7g93 / PYSEC-2026-3493
More information
Details
Summary
When Pillow loads an uncompressed image whose tile uses the
rawcodec and a mode inImage._MAPMODES, and the image was opened from a filename, it memory-maps the file and builds the image's row pointers directly into the mapping viaPyImaging_MapBuffer(src/map.c). The per-row spacing (stride) is taken from the tile arguments.map.cvalidatesoffset + ysize*stride <= buffer_lenbut never checks thatstrideis at least the natural row widthxsize * pixelsize.The McIdas AREA plugin (
McIdasImagePlugin.py) derivesstride,offset,xsize, andysizedirectly from attacker-controlled 32-bit header words with no validation. By supplying astridefar smaller than the row width, an attacker makes each row pointer readxsize*pixelsizebytes that run past the mapped region. Accessing the pixels (e.g.Image.tobytes(),getpixel,convert,save) then reads adjacent process memory (information disclosure) or faults (SIGBUS, denial of service).Complete Code Trace
Step 1:
McIdasImageFile._open- turns attacker header words into image size, file offset, and row stride with no validation.Step 2:
ImageFile.load(mmap branch) - selects mmap and delegates tomap_buffer.Step 3:
PyImaging_MapBuffer- builds row pointers atstridespacing into the mmap; validates everything exceptstride >= row width.im->linesize(the number of bytes any consumer reads per row) isxsize * pixelsize = 200000, but the row pointers are onlystride = 1byte apart and the buffer is onlyoffset + ysize*stride = 2bytes "claimed". Nothing reconciles the two.Step 4: pixel access (
Image.tobytes()→ raw encodercopy1) - readslinesizebytes fromim->image[0], i.e.xsizebytes starting atview.buf + offset, running far past the mmap.Chain Summary
Proof of Concept
See attached poc.zip
Impact on a Parent Application
Any application that opens image files supplied by users from a path on disk (the common pattern: save upload to a temp file, then
Image.open(path)), has the default plugin set (McIdas is registered by default), and subsequently reads/returns/re-encodes the decoded pixels (thumbnailing, format conversion, serving a preview), is exposed:xsizereliably crashes the worker with SIGBUS.Suggested fix
Core fix in
src/map.c(PyImaging_MapBuffer): rejectoffset < 0andstride < im->linesize. Defense-in-depth inMcIdasImagePlugin._open: rejectoffset < 0orstride < xsize*pixelsize.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Pillow: Heap out-of-bounds write
Image.paste()/Image.crop()via signed coordinate overflowBIT-pillow-2026-59199 / CVE-2026-59199 / GHSA-6r8x-57c9-28j4 / PYSEC-2026-3451
More information
Details
Summary
Pillow's public image coordinate APIs can trigger a native heap out-of-bounds
write when given coordinates near the signed 32-bit integer limits. In 4-byte
pixel modes such as
RGBA, this becomes a controlled backward heap underwrite:for a source image of width
W, Pillow writes4 * Wattacker-controlled bytesstarting
4 * Wbytes before the destination row pointer. With successful largeimage allocation, the theoretical upper bound is ~2 GiB backwards from
the destination row.
Minimal public API trigger:
The same root cause is also reachable through
Image.crop()andImage.alpha_composite(). No private API, ctypes, custom Python object, ormalformed image file is needed.
This has been confirmed as an ASAN heap-buffer-overflow write. On normal
non-ASAN Pillow builds, the minimal trigger corrupts the heap and aborts with
double free or corruption (out)Details
src/PIL/Image.py:paste()accepts a 4-tuple box and passes it to the nativeImagingCore.paste()method:src/_imaging.c:_paste()parses the four Python coordinates into signedintvalues and calls
ImagingPaste():src/libImaging/Paste.c:ImagingPaste()computes and clips the region usingsigned
intarithmetic:With
dx0 = 2147483646anddx1 = -2147483648,dx1 - dx0wraps to2.That matches the 2-pixel source image, so the size check passes. The later
dx0 + xsizeclip check wraps around and does not reject the out-of-boundsdestination.
For 4-byte pixel modes such as
RGBA, the paste loop then multipliesdxbypixelsize:For the minimal PoC, this writes 8 attacker-controlled bytes 8 bytes before the
destination row allocation.
The primitive scales with the attacker-controlled source width:
Examples for
RGBA:Pillow's image creation guard currently limits
xsizeto roughlyINT_MAX / 4 - 1, so the theoretical upper bound for thisRGBAunderwrite is2,147,483,640bytes before the destination row pointer. In practice, theusable range depends on memory availability, allocator layout, and process heap
state.
Two other documented APIs reach the same sink:
Image.crop()keepsright - leftsmall, so the Python decompression-bombcheck allows it.
src/libImaging/Crop.cthen computes wrapped pastecoordinates and calls
ImagingPaste().PoC
The following standalone script exercises all three public API paths. Save it
as
b021_poc.pyand run it withpaste,crop, oralpha.Run against an ASAN build:
Observed ASAN signature for the direct
Image.paste()path:On non-ASAN Pillow
12.2.0and local12.3.0.dev0, the direct minimalImage.paste()trigger returns frompaste()and then the process abortsduring cleanup with:
Observed ASAN signature for the
Image.crop()andImage.alpha_composite()paths:
Suggested fix
Avoid signed overflow in paste/crop coordinate arithmetic. Use checked
arithmetic or a wider type before calculating widths and clipped endpoints.
For example, reject boxes whose endpoint subtraction cannot be represented
cleanly, and clip using non-overflowing comparisons:
ImagingCrop()should receive the same treatment forsx1 - sx0,dx0 = -sx0, anddx1 = imIn->xsize - sx0.Impact
This is a heap out-of-bounds write in Pillow's native C extension, reachable
through documented public image APIs.
Applications are impacted if an untrusted user can control image operation
coordinates passed to Pillow, for example crop boxes, paste boxes, or overlay
positions. The bytes written in the direct
Image.paste()variant are copiedfrom the source image, so attacker-controlled source pixels can influence the
out-of-bounds write. For
RGBA, the write is a backward heap underwrite whoseoffset and length are both
4 * source_width, bounded in practice by successfulimage allocation and heap layout.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Pillow
PcfFontFile._load_bitmaps():Image.frombytes()called without_decompression_bomb_check()— bomb protection bypass via PCF font loadingBIT-pillow-2026-54059 / CVE-2026-54059 / GHSA-8v84-f9pq-wr9x / PYSEC-2026-2253
More information
Details
Description
PIL/PcfFontFile.py_load_bitmaps()(line 227) reads glyph dimensions from the PCFMETRICSsection and passes them directly toImage.frombytes()without callingImage._decompression_bomb_check(). Dimensions originate from unsigned 16-bit values:Maximum exploitable pixel count: 65,535 × 131,070 = 8,589,734,450 pixels — 48× the DecompressionBombError threshold.
Vulnerable code (
PIL/PcfFontFile.pyline 224–227):Image.frombytes()callsImage.new()first (allocating the full C-heap buffer), then attempts to fill it. This creates two distinct attack paths:frombytes()succeeds → image stored infont.glyph[ch]permanentlyImage.new()allocates the full buffer →ValueError→ buffer freed → but the spike occurs before Python can respondSteps to reproduce
Proof of Concept script:
Expected output:
Amplification table:
Impact
PcfFontFile(fp)) is affectedPcfFontFileis never loaded viaImage.open(), so the bomb check protection is completely absent from the entire PCF font loading pathpython-pillow/Pillowmainbranch as of 2026-06-07Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Pillow: Controlled heap out-of-bounds write in Pillow
ImageCmsTransform.apply()via output mode mismatchBIT-pillow-2026-59205 / CVE-2026-59205 / GHSA-9hw9-ch79-4vh6 / PYSEC-2026-3453
More information
Details
Summary
Pillow's public
ImageCms.ImageCmsTransform.apply(im, imOut)API can triggercontrolled native heap corruption when the caller supplies an output image whose
mode does not match the transform's declared output mode.
For example, a transform built as
RGBA -> RGBAcan be applied to anLoutputimage. Pillow checks dimensions only, then calls LittleCMS with the output row
pointer. LittleCMS writes RGBA-sized rows into a 1-byte-per-pixel
Limage row.Details
src/PIL/ImageCms.py:ImageCmsTransform.apply()accepts an optional callersupplied
imOut:If
imOutis provided, Pillow does not check:The C wrapper in
src/_imagingcms.cunwraps both image cores and only checksthat the output dimensions are at least as large as the input dimensions:
findLCMStype()mapsRGB,RGBA, andRGBXtransform modes to LittleCMSTYPE_RGBA_8, which writes 4 bytes per pixel:So with a transform declared as
RGBA -> RGBA, LittleCMS writes4 * widthbytes to each output row. If the supplied output image is mode
L, Pillow onlyallocated
1 * widthbytes for that row.For width 4096:
The bug does not require a large image. Width 8 was enough to corrupt heap
metadata. At width 8,
apply()returned to Python and printedafter; glibcdetected the corrupted heap later during cleanup.
PoC
Tiny heap corruption trigger:
Observed locally on Pillow
12.3.0.dev0:Controlled overwrite evidence PoC:
Run under gdb:
Observed on Pillow
12.3.0.dev0:0x4443424144434241is the attacker-controlled source pixel patternb"ABCDABCD"interpreted as a little-endian pointer-sized value.Using source pixels
(1, 2, 3, 4)similarly produced a faulting pointer of0x403020104030201, matching the repeated pixel bytes.Impact
This is a heap out-of-bounds write in Pillow's native ImageCms extension,
reachable through public API.
Applications are impacted if untrusted users can control ImageCms transform
parameters and/or provide the output image object passed to
ImageCmsTransform.apply(). The source image pixels influence the bytes writtenout of bounds.
Suggested fix
Validate modes before calling into the native transform:
The C extension should also defensively reject mismatched image modes before
calling
cmsDoTransform().Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
BIT-pillow-2026-59198 / CVE-2026-59198 / GHSA-fj7v-r99m-22gq / PYSEC-2026-3494
More information
Details
Summary
Pillow's TGA RLE encoder reads past its row buffer when saving a mode
"1"image. Adjacent process heap bytes can be copied into the generated TGA file.
The bug is reachable through the public save API:
Older affected Pillow versions use the equivalent public option
rle=True.For mode
"1", Pillow allocates a packed row buffer ofceil(width / 8)bytes, but
ImagingTgaRleEncode()treats the row as one full byte per pixel.The maximum valid TGA width is
65535. At that width:On non-ASAN Pillow
12.2.0, the public-only maximum-width PoC below serialized57297bytes from distinct out-of-bounds source offsets into one returned TGA,covering
99.92%of the maximum adjacent heap window. No heap grooming, ctypes,private API, or malformed input file was used. The disclosure is emitted across
many TGA packet payload copies of at most
128bytes each, not one largememcpy().Details
src/PIL/TgaImagePlugin.pyallows mode"1"TGA output and selects thetga_rleencoder when RLE compression is requested.src/encode.c:_setimage()allocates the row buffer using the packed-bitformula:
For mode
"1",state->bits == 1.src/libImaging/TgaRleEncode.cthen computes:This becomes
1, and the encoder uses pixel indexes as byte offsets:The packet payload
memcpy()later copies those out-of-bounds source bytes intothe output. Raw packets copy up to
128contiguous bytes, while RLE packets copyone representative byte:
A width-2 mode
"1"image allocates one row byte and already triggers an ASANheap-buffer-overflow read. Wider images increase the adjacent heap window and
the amount of heap data that can be serialized.
PoC
Minimal ASAN trigger
Observed on local Pillow
12.3.0.dev0ASAN target:Maximum-width heap disclosure
This PoC uses one maximum-width row. It parses the generated TGA packets and
extracts only payload bytes whose source offsets were outside the allocated
packed row. Rows are avoided because they mostly repeat the same adjacent heap window.
Run the following with a standard affected Pillow installation.
Observed on installed Pillow
12.2.0:Impact
This is a heap out-of-bounds read and potential information disclosure.
A maximum-width single-row image can cause nearly the full
57343-byte adjacent heap window to be incorporated i