
#CVE-2026-54060 - Supply chain attack in Pillow #Python imaging library. #FontFile.compile() bypasses decompression bomb check, enabling excessive memory allocation. #CVSS 7.5. Update to Pillow 12.3.0 immediately. #CVEAlert #infosec #devsecops #devops #git #github #gitlab https://www.valtersit.com/cve/CVE-2026-54060
Post summary
A supply‑chain vulnerability in Pillow allows memory exhaustion by bypassing the decompression bomb check; the post urges users to upgrade to version 12.3.0 and notes a CVSS score of 7.5.
