---
schema_version: '1.0'
id: security-20260711-dad7c4
url: https://osv.dev/vulnerability/PYSEC-2026-165
url_hash: dad7c45414a15e79148a228b14c07508d7ad1e4d46f3ee268c63743f9051c2fd
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-165
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-42308
- PYSEC-2026-165
- severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- pillow
- PyPI
lang: en
published_at: '2026-05-09T06:16:09Z'
fetched_at: '2026-07-11T06:37:18Z'
updated_at: '2026-07-11T06:39:54Z'
status: published
content_hash: 03458d5229456a1f35749ad249a031598bd3e665e6f91d6d2db0547dc6288715
license_note: full
summary: Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances
  for each glyph by an exceeding large amount, when Pillow keeps track of the current
  position, it may lead to an integer overflow. This issue has been patched in version
  12.2.0.
summary_source: rss
summary_en: Pillow is a Python imaging library. Prior to version 12.2.0, if a font
  advances for each glyph by an exceeding large amount, when Pillow keeps track of
  the current position, it may lead to an integer overflow. This issue has been patched
  in version 12.2.0.
entities: []
key_facts: []
related: []
related_auto: []
title: CVE-2026-42308 — pillow
---

# CVE-2026-42308 — pillow

## TL;DR
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.

## Key Points
- cve / CVE-2026-42308 / PYSEC-2026-165 / severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H / pillow / PyPI

## Details
**Severity:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
**Advisory:** PYSEC-2026-165 (CVE-2026-42308)

**Affected (your watchlist):**
- `PyPI:pillow` 12.1.1 → fixed in 12.2.0 [docker/docker-llmwiki]

**Details:**
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.

**References:**
- https://github.com/python-pillow/Pillow/releases/tag/12.2.0
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-165_

## Source
元記事: [CVE-2026-42308 — pillow](https://osv.dev/vulnerability/PYSEC-2026-165) — published 2026-05-09T06:16:09Z
