Logo
vulnerabilityCVE-2026-59203
Name
CVE-2026-59203
Source
NVD ( link)Debian ( link)
Description
Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to the same directive and parse it repeatedly in an infinite loop. This issue is fixed in version 12.3.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python-pillow
Exploitable

Vulnerability Ratings#


5.3
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
11.1.0
Not Affected
openwrt
master
12.2.0-r2
Exploitable
openwrt
openwrt-25.12
12.1.1-r1
Exploitable
yocto
kirkstone
9.4.0
Not Affected
yocto
master
12.3.0
Not Affected
yocto
scarthgap
10.3.0
Not Affected