CVE-2026-40192Disclosure(python / pillow)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch python pillow systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770CWE-409

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pillow

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-16); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
pillow

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-16: 2Mentions · 2026-04-25: 1PoC Mentioned / Linked · 2026-04-25: 1Patch / Workaround · 2026-04-25: 1Technical Details · 2026-04-16: 2Technical Details · 2026-04-25: 104-1604-25
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-162
Disclosure1General1
2026-04-251
Patch1
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    CVE-2026-40192 (Pillow decompression bomb) is old news. But your next CVE isn’t. Here’s a bash script to auto-patch this image DoS bug on Fedora. And the book to crush future CVEs before they hit. Read more -> https://tinyurl.com/4p4vpk4d #Fedora https://t.co/9sPjctJZYj

    Post summary

    The tweet announces CVE‑2026‑40192, provides a Bash script to auto‑patch the image DoS bug on Fedora, and links to additional resources, but does not report active exploitation or an exploit tool.

    1000066
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40192 Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulne… https://www.cve.org/CVERecord?id=CVE-2026-40192

    Post summary

    The snippet presents a concise disclosure of CVE‑2026‑40192, noting that Pillow versions 10.3.0‑12.1.1 allow unlimited GZIP‑compressed data to be read during FITS image decoding.

    0000088
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40192 Decompression Bomb Vulnerability in Pillow FITS Image Decoder Ver... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40192 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A short alert announcing CVE-2026-40192, a decompression bomb vulnerability in Pillow FITS Image Decoder, without mention of PoC, exploits, patches, or active exploitation.

    0000033
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonpillow---

Explore more