CVE Vulnerabilities

CVE-2026-59200

Uncontrolled Resource Consumption

Published: Jul 14, 2026 | Modified: Jul 21, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.

Weakness

The product does not properly control the allocation and maintenance of a limited resource.

Affected Software

NameVendorStart VersionEnd Version
PillowPython5.1.0 (including)12.3.0 (excluding)
Red Hat AI Inference Server 3.3RedHatrhaiis/model-opt-cuda-rhel9:1787601159*
Red Hat AI Inference Server 3.4RedHatrhaii/vllm-spyre-rhel9:1789681201*
Red Hat AI Inference Server 3.4RedHatrhaii/vllm-cpu-rhel9:1789681128*
Red Hat AI Inference Server 3.4RedHatrhaii/vllm-cuda-rhel9:1789681126*
Red Hat AI Inference Server 3.4RedHatrhaii/model-opt-cuda-rhel9:1789681126*
Red Hat AI Inference Server 3.4RedHatrhaii/vllm-rocm-rhel9:1789681126*
Red Hat AI Inference Server 3.4RedHatrhaii/vllm-cpu-rhel9:1790075793*
Red Hat AI Inference Server 3.4RedHatrhaii/vllm-spyre-rhel9:1790076141*
Red Hat AI Inference Server 3.4RedHatrhaii/vllm-cuda-rhel9:1790090131*
Red Hat AI Inference Server 3.4RedHatrhaii/vllm-rocm-rhel9:1790109620*
Red Hat AI Inference Server 3.4RedHatrhaii/model-opt-cuda-rhel9:1790076498*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/disk-image-cuda-rhel9:1788290314*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/bootc-aws-cuda-rhel9:1788273908*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/bootc-azure-cuda-rhel9:1788273909*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/bootc-cuda-rhel9:1788260684*
Red Hat Enterprise Linux AI 3.3RedHatrhelai3/bootc-gcp-cuda-rhel9:1788273977*
Red Hat Enterprise Linux AI 3.4RedHatrhelai3/disk-image-cuda-rhel9:1790957417*
Red Hat Enterprise Linux AI 3.4RedHatrhelai3/bootc-aws-cuda-rhel9:1790881122*
Red Hat Enterprise Linux AI 3.4RedHatrhelai3/bootc-azure-cuda-rhel9:1790881120*
Red Hat Enterprise Linux AI 3.4RedHatrhelai3/bootc-azure-rocm-rhel9:1790707552*
Red Hat Enterprise Linux AI 3.4RedHatrhelai3/bootc-cuda-rhel9:1790868254*
Red Hat Enterprise Linux AI 3.4RedHatrhelai3/bootc-gcp-cuda-rhel9:1790881123*
Red Hat Enterprise Linux AI 3.4RedHatrhelai3/bootc-rocm-rhel9:1790614447*
Red Hat OpenShift AI 3.3RedHatrhoai/odh-llm-d-inference-scheduler-rhel9:1789662430*
Red Hat OpenShift AI 3.3RedHatrhoai/odh-mlflow-rhel9:1789653606*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-automl-rhel9:1786612415*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-autorag-rhel9:1786612637*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-llm-d-kv-cache-rhel9:1787169432*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-mlflow-rhel9:1787226790*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-openvino-model-server-rhel9:1787303251*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1787073866*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1787073873*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:1787073459*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1787073611*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:1787073451*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1787073451*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-th06-cpu-torch210-py312-rhel9:1787076778*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-th06-cuda130-torch210-py312-rhel9:1787077779*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-th06-rocm64-torch291-py312-rhel9:1787076481*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-training-cuda128-torch29-py312-rhel9:1786611803*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-training-rocm64-torch29-py312-rhel9:1786611435*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-trustyai-garak-lls-provider-dsp-rhel9:1786613209*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1787121387*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1787074331*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1787073605*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1787073546*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1787073717*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1787073713*
Red Hat OpenShift AI 3.4RedHatrhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1787073593*
Red Hat Quay 3.10RedHatquay/quay-rhel8:1786395065*
Red Hat Quay 3.12RedHatquay/quay-rhel8:1786170635*
Red Hat Quay 3.14RedHatquay/quay-rhel8:1788593843*
Red Hat Quay 3.15RedHatquay/quay-rhel8:1785261506*
Red Hat Quay 3.16RedHatquay/quay-rhel9:1789563753*
Red Hat Quay 3.17RedHatquay/quay-rhel9:1786181981*
Red Hat Quay 3.9RedHatquay/quay-rhel8:1785950004*
PillowUbuntuupstream*

Potential Mitigations

  • Mitigation of resource exhaustion attacks requires that the target system either:

  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.

  • The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.

References