CVE-2026-42308

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-09 06:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-42308

Mitre link : CVE-2026-42308

CVE.ORG link : CVE-2026-42308


JSON object : View

Products Affected

python

  • pillow
CWE
CWE-190

Integer Overflow or Wraparound