{"id":"CVE-2026-54060","aliases":["BIT-pillow-2026-54060","GHSA-5x94-69rx-g8h2","PYSEC-2026-2254"],"url":"https://o3.security/vulnerability/CVE-2026-54060","summary":"Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`","details":"Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(\"1\", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.","published":"2026-07-06T18:49:23.788Z","modified":"2026-08-12T03:51:19.911506387Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pillow","fixedVersion":"12.3.0"}],"fix":{"url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d","label":"python-pillow/Pillow@0a263e6"},"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54060.json"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54060"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:19.911506387Z"}}