CVE-2026-42308
MEDIUM SEVERITYVulnerability Description
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-190
Source
GitHub
Vendor
pip
Product
pillow
Discussion (0)
Add Comment
No comments yet. Be the first!