CVE-2026-54059
python-pillow Pillow, pillow
Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.
- CVSS
- 7.5
- EPSS
- 0.41% 33.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.07