From 8e426bb616383408f8fffcdcd00a2c9dc40661f9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?St=C3=A9phane=20Wirtel?= Date: Thu, 24 Sep 2026 07:51:29 +0200 Subject: [PATCH] fix(deps): upgrade pillow to 12.3.0 for security fixes Resolves multiple high/medium severity Dependabot alerts: heap out-of-bounds writes in ImageCmsTransform.apply(), Image.paste()/crop() and ImageFilter.RankFilter, a JPEG2000 tiled-decode DoS, a decompression bomb in PdfParser, a TGA RLE encoder heap data leak, an OS command injection in WindowsViewer.get_command(), several decompression-bomb check bypasses (GdImageFile, BdfFontFile, FontFile, PcfFontFile), an out-of-bounds read via row stride on the mmap path, and an infinite loop DoS in EpsImagePlugin. GHSA-9hw9-ch79-4vh6, GHSA-vjc4-5qp5-m44j, GHSA-jjj6-mw9f-p565, GHSA-6r8x-57c9-28j4, GHSA-fj7v-r99m-22gq, GHSA-xj96-63gp-2gmr, GHSA-4x4j-2g7c-83w6, GHSA-phj9-mv4w-65pm, GHSA-45hq-cxwh-f6vc, GHSA-5x94-69rx-g8h2, GHSA-8v84-f9pq-wr9x, GHSA-62p4-gmf7-7g93, GHSA-pg7v-jwj7-p798 Co-Authored-By: Claude Sonnet 5 --- requirements/dev.txt | 2 +- requirements/main.txt | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/requirements/dev.txt b/requirements/dev.txt index 69df7eb..993a357 100644 --- a/requirements/dev.txt +++ b/requirements/dev.txt @@ -140,7 +140,7 @@ packaging==26.2 # pip-audit # pip-requirements-parser # pipdeptree -pillow==12.2.0 +pillow==12.3.0 # via # -c requirements/main.txt # pillow-heif diff --git a/requirements/main.txt b/requirements/main.txt index f0de1c2..f1b76e7 100644 --- a/requirements/main.txt +++ b/requirements/main.txt @@ -117,7 +117,7 @@ packaging==26.2 # via gunicorn pandas==3.0.3 # via -r requirements/main.in -pillow==12.2.0 +pillow==12.3.0 # via # pillow-heif # wagtail