GHSA-wjx4-4jcj-g98jMediumCVSS 5.5

Pillow has an integer overflow when processing fonts

Published
May 4, 2026
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

If a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This has been fixed.

🎯 Affected products1

  • pip/pillow:< 12.2.0

🔗 References (5)