GHSA-wjx4-4jcj-g98jMediumCVSS 5.5
Pillow has an integer overflow when processing fonts
🔗 CVE IDs covered (1)
📋 Description
If a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This has been fixed.
🎯 Affected products1
- pip/pillow:< 12.2.0
🔗 References (5)
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j
- https://nvd.nist.gov/vuln/detail/CVE-2026-42308
- https://github.com/python-pillow/Pillow/releases/tag/12.2.0
- https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml
- https://github.com/advisories/GHSA-wjx4-4jcj-g98j