We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 2de1bf2 commit ae43cdaCopy full SHA for ae43cda
docs/releasenotes/10.0.0.rst
@@ -157,10 +157,15 @@ TODO
157
Security
158
========
159
160
-TODO
161
-^^^^
+Limit size even if one dimension is zero
+^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
162
163
+When performing decompression bomb checks, Pillow did not reject images with
164
+excessive width and zero height, or zero width and excessive height. That has
165
+now been fixed.
166
+
167
+This effectively dates to the PIL fork, since problem images would still have
168
+been processed before Pillow started checking for decompression bombs.
169
170
Other Changes
171
=============
0 commit comments