Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wjx4-4jcj-g98j | Pillow has an integer overflow when processing fonts |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 09 May 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python-pillow
Python-pillow pillow |
|
| Vendors & Products |
Python-pillow
Python-pillow pillow |
Sat, 09 May 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0. | |
| Title | Pillow: Integer overflow when processing fonts | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-09T04:09:01.631Z
Reserved: 2026-04-26T12:37:18.169Z
Link: CVE-2026-42308
No data.
Status : Received
Published: 2026-05-09T06:16:09.793
Modified: 2026-05-09T06:16:09.793
Link: CVE-2026-42308
No data.
OpenCVE Enrichment
Updated: 2026-05-09T06:30:25Z
Weaknesses
Github GHSA