Vulnerability DatabaseGHSA-jgpv-4h4c-xhw3

GHSA-jgpv-4h4c-xhw3
Python vulnerability analysis and mitigation

Overview

A moderate severity vulnerability was identified in Pillow versions prior to 8.1.1, tracked as GHSA-jgpv-4h4c-xhw3. The vulnerability relates to improper validation of image sizes within BLP containers, which could lead to uncontrolled resource consumption. The issue was published on April 22, 2021, and affects the Python imaging library Pillow (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption) and stems from inadequate validation of reported image sizes within BLP containers. When processing specially crafted invalid image files, the application fails to properly verify the contained image size, potentially leading to excessive memory allocation attempts (GitHub Advisory).

Impact

The vulnerability can be exploited to cause a denial of service condition through excessive memory consumption. When processing maliciously crafted image files, the application may attempt to allocate extremely large amounts of memory or spend an unusually long time processing the image (GitHub Advisory).

Exploitability

The vulnerability requires an attacker to supply specially crafted invalid image files to a system using an affected version of Pillow. The exploitation can lead to resource exhaustion through memory consumption (GitHub Advisory).

Mitigation and workarounds

Users should upgrade to Pillow version 8.1.2 or later, which contains patches for this vulnerability. Systems that cannot be immediately updated should implement controls to validate image files before processing them with Pillow (GitHub Advisory).

Community reactions

Several organizations have evaluated the impact of this vulnerability on their systems. For instance, Palo Alto Networks confirmed that their PAN-OS is not affected as it does not process untrusted images with Pillow (Palo Alto).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59714HIGH7.1
  • Python logoPython
  • cpe:2.3:a:openwebui:open_webui
NoYesAug 13, 2026
CVE-2026-48099HIGH7.1
  • Python logoPython
  • python3-wsgidav+pam
NoYesAug 13, 2026
CVE-2026-45725HIGH7.1
  • Python logoPython
  • compliance-trestle
NoYesAug 13, 2026
CVE-2026-73652HIGH7.1
  • Python logoPython
  • vantage6
NoNoAug 13, 2026
CVE-2026-45774MEDIUM6.9
  • Python logoPython
  • compliance-trestle
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management