Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wjx4-4jcj-g98j | Pillow has an integer overflow when processing fonts |
Sat, 16 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 12 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python
Python pillow |
|
| CPEs | cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Python
Python pillow |
|
| Metrics |
cvssV3_1
|
Mon, 11 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 09 May 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python-pillow
Python-pillow pillow |
|
| Vendors & Products |
Python-pillow
Python-pillow pillow |
Sat, 09 May 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0. | |
| Title | Pillow: Integer overflow when processing fonts | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T15:03:00.916Z
Reserved: 2026-04-26T12:37:18.169Z
Link: CVE-2026-42308
Updated: 2026-05-11T15:02:57.971Z
Status : Analyzed
Published: 2026-05-09T06:16:09.793
Modified: 2026-05-12T17:57:20.027
Link: CVE-2026-42308
OpenCVE Enrichment
Updated: 2026-05-09T06:30:25Z
Github GHSA