CVE-2026-59200·Python vulnerability
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.
- Severity
- high
- Software
- Python
- Fixed in
- 12.3.0
- Published
- 2026-07-14
Affected versions
From: 5.1.0
Until: 12.3.0
Fixed in: 12.3.0
How to fix this CVE
Update Python's Pillow imaging library to version 12.3.0 or later to patch a memory exhaustion vulnerability in PDF stream decompression. The vulnerability allows specially crafted PDF files to consume excessive memory, potentially causing denial of service. Immediately apply patches to all systems processing untrusted PDF files through Python applications.
sudo dnf update python3-pillowDefensia detects this vulnerability
How to check if you are affected
- Check installed Pillow version: python3 -c 'import PIL; print(PIL.__version__)'
- Identify Python applications that process PDF files: grep -r 'PdfParser\|PIL.PdfImagePlugin' /opt /home /srv --include='*.py' 2>/dev/null
- Search system logs for memory exhaustion events during PDF processing: journalctl -u {service_name} | grep -i 'memory\|oom\|killed'
- Verify patched version by running: python3 -c 'import PIL; assert PIL.__version__ >= "12.3.0", "Vulnerable version detected"'
FAQ
What is CVE-2026-59200?
A memory exhaustion vulnerability in Pillow's PDF stream decoder that fails to validate decompression output sizes, allowing attackers to trigger out-of-memory conditions by submitting specially crafted PDF files with FlateDecode streams.
Is CVE-2026-59200 being actively exploited?
No, there are currently no known active exploits or CISA KEV listings for this vulnerability, but the low barrier to exploitation warrants prompt patching.
What versions of Python are affected by CVE-2026-59200?
Pillow versions 5.1.0 through 12.2.0 are vulnerable; Python 3.x environments using these Pillow versions are affected. The vulnerability is resolved in Pillow 12.3.0 and later.
How do I check if my server is vulnerable to CVE-2026-59200?
Run: python3 -c 'import PIL; v = tuple(map(int, PIL.__version__.split("."))); print("VULNERABLE" if (5,1,0) <= v < (12,3,0) else "PATCHED")' and review which applications depend on Pillow for PDF handling.
Does Defensia detect CVE-2026-59200?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Python and Pillow are installed on a monitored server, CVE-2026-59200 will appear in your dashboard with remediation steps.
Related Python CVEs
References
- https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09
- https://github.com/python-pillow/Pillow/pull/9718
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-59200. Free for 1 server.
Get started free