FlawAtlas
Search the atlas
OPENSUSE-SU-2026:20617-1 Not scored

Security update for python-Pillow

This update for python-Pillow fixes the following issue: - CVE-2026-40192: Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks (bsc#1262184).

Exploit probability Not scored
Published April 22, 2026
Required by Not available
Last source change April 25, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 16.0 python-Pillow

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:20617-1

This update for python-Pillow fixes the following issue: - CVE-2026-40192: Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks (bsc#1262184).

View original source

05 / REFERENCES

Further evidence