THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-40192 (HIGH 7.5) — Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leadi

[NVD] CVE-2026-40192 (HIGH 7.5) — Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leadi

lownvdPublished 2026-04-15

CVE-2026-40192 CVSS: 7.5 HIGH Published: 2026-04-15T23:16:10.053

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performan

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40192