Pillow has an integer overflow when processing fonts
Moderate severity
GitHub Reviewed
Published
Apr 23, 2026
in
python-pillow/Pillow
•
Updated Jun 8, 2026
Description
Published to the GitHub Advisory Database
May 4, 2026
Reviewed
May 4, 2026
Published by the National Vulnerability Database
May 9, 2026
Last updated
Jun 8, 2026
If a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This has been fixed.
References