{"id":"CVE-2026-42310","summary":"Pillow: PDF Parsing Trailer Infinite Loop (DoS)","details":"Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.","aliases":["BIT-pillow-2026-42310","GHSA-r73j-pqj5-w3x7"],"modified":"2026-06-18T03:55:22.219934762Z","published":"2026-05-09T04:10:48.395Z","related":["CGA-9w22-5cq6-3php","SUSE-SU-2026:1842-1","SUSE-SU-2026:21861-1","SUSE-SU-2026:2234-1","openSUSE-SU-2026:20831-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-835"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42310.json"},"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42310.json"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-r73j-pqj5-w3x7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42310"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/3bf614e4b8615d0ce1d5039efaf6db447fe7c468"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9519"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/python-pillow/pillow","events":[{"introduced":"acb19d8e45699bf961604e48b28002b099250ddd"},{"fixed":"3c41c095064200a02672d89cc5ff629eaf4b0d4f"},{"fixed":"3bf614e4b8615d0ce1d5039efaf6db447fe7c468"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"extracted_events":[{"introduced":"4.2.0"},{"fixed":"12.2.0"}],"cpe":"cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*"}}],"versions":["12.1.0","12.0.0","11.3.0","11.2.1","11.1.0","11.0.0","10.4.0","10.3.0","10.2.0","10.1.0","10.0.0","9.5.0","9.4.0","9.3.0","9.2.0","9.1.0","9.0.0","8.4.0","8.3.0","8.2.0","8.1.0","8.0.0","7.2.0","7.1.0","7.0.0","6.2.0","6.1.0","6.0.0","5.4.0","5.3.0","5.2.0","5.1.0","5.0.0","4.3.0","4.2.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42310.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}