---
schema_version: '1.0'
id: security-20260711-202b54
url: https://osv.dev/vulnerability/GHSA-wjx4-4jcj-g98j
url_hash: 202b543284a45f06361d85b5c163b944412bedebd64614be3c66600c4785b2d4
canonical_url: https://osv.dev/vulnerability/GHSA-wjx4-4jcj-g98j
source: osv:ghsa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-42308
- GHSA-wjx4-4jcj-g98j
- severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- pillow
- PyPI
lang: en
published_at: '2026-05-04T20:18:45Z'
fetched_at: '2026-07-11T06:37:18Z'
updated_at: '2026-07-11T06:39:54Z'
status: published
content_hash: c963e39da5c0cdd290cb3b3281749068a84aa144b248e6ea11dce92cf2c75d12
license_note: full
summary: Pillow has an integer overflow when processing fonts
summary_source: rss
summary_en: Pillow has an integer overflow when processing fonts
entities:
- name: HashTag
  type: concept
key_facts: []
related: []
related_auto:
- name: SustainableQuantumComputing
  type: concept
  weight: 3.0
title: 'CVE-2026-42308: Pillow has an integer overflow when processing fonts'
---

# CVE-2026-42308: Pillow has an integer overflow when processing fonts

## TL;DR
Pillow has an integer overflow when processing fonts

## Key Points
- cve / CVE-2026-42308 / GHSA-wjx4-4jcj-g98j / severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H / pillow / PyPI

## Details
**Severity:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
**Advisory:** GHSA-wjx4-4jcj-g98j (CVE-2026-42308)

**Affected (your watchlist):**
- `PyPI:pillow` 12.1.1 → fixed in 12.2.0 [docker/docker-llmwiki]

**Details:**
If a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This has been fixed.

**References:**
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j
- https://nvd.nist.gov/vuln/detail/CVE-2026-42308
- https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-165.yaml
- https://github.com/python-pillow/Pillow
- https://github.com/python-pillow/Pillow/releases/tag/12.2.0

_Data: OSV.dev (upstream: ghsa) — https://osv.dev/vulnerability/GHSA-wjx4-4jcj-g98j_

## Source
元記事: [CVE-2026-42308: Pillow has an integer overflow when processing fonts](https://osv.dev/vulnerability/GHSA-wjx4-4jcj-g98j) — published 2026-05-04T20:18:45Z
