HIGH 7.5 PyPI
CVE-2026-59203
PYSEC-2026-3452 · BIT-pillow-2026-59203 · CVE-2026-59203 · GHSA-pg7v-jwj7-p798
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to the same directive and parse it repeatedly in an infinite loop. This issue is fixed in version 12.3.0.
References
- ADVISORY https://github.com/python-pillow/Pillow/releases/tag/12.3.0
- FIX https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83
- FIX https://github.com/python-pillow/Pillow/pull/9708
- EVIDENCE https://github.com/python-pillow/Pillow/security/advisories/GHSA-pg7v-jwj7-p798
Ready to move
Start Securing
Free, no credit card | First findings in minutes