THREAT OPS › Threat News › [NVD] CVE-2026-40192 (HIGH 7.5) — Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leadi
[NVD] CVE-2026-40192 (HIGH 7.5) — Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leadi
CVE-2026-40192 CVSS: 7.5 HIGH Published: 2026-04-15T23:16:10.053
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performan
Indicators of compromise
- CVE-2026-40192cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40192