CVE-2026-42310

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-09 06:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-42310

Mitre link : CVE-2026-42310

CVE.ORG link : CVE-2026-42310


JSON object : View

Products Affected

python

  • pillow
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')