Skip to content

Add decompression bomb check to grabclipboard() on Windows - #10078

Merged
radarhere merged 3 commits into
python-pillow:mainfrom
radarhere:grab
Sep 29, 2026
Merged

radarhere merged 3 commits into
python-pillow:mainfrom
radarhere:grab

Conversation

@radarhere

Copy link
Copy Markdown
Member

At the moment, grabclipboard() on Windows may bypass Image.open() when loading the image data.

Pillow/src/PIL/ImageGrab.py

Lines 184 to 192 in 7cb0e02

data = io.BytesIO(data)
if fmt == "png":
from . import PngImagePlugin
return PngImagePlugin.PngImageFile(data)
elif fmt == "DIB":
from . import BmpImagePlugin
return BmpImagePlugin.DibImageFile(data)

This means that they avoid running

_decompression_bomb_check(im.size)

Switching to Image.open() adds this check.

@akx akx left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. A couple of comment suggestions to make the life of future reviewers a bit easier?

Comment thread src/display.c
Comment thread src/display.c
UINT format;
UINT formats[] = {CF_DIB, CF_DIBV5, CF_HDROP, RegisterClipboardFormatA("PNG"), 0};
LPCSTR format_names[] = {"DIB", "DIB", "file", "png", NULL};
LPCSTR format_names[] = {"DIB", "DIB", "file", "PNG", NULL};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
LPCSTR format_names[] = {"DIB", "DIB", "file", "PNG", NULL};
// Pillow format names in the same order as the formats above
LPCSTR format_names[] = {"DIB", "DIB", "file", "PNG", NULL};

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

...they're not exactly 'Pillow format names'. 'DIB' and 'PNG are, but 'file' isn't.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fair:

Suggested change
LPCSTR format_names[] = {"DIB", "DIB", "file", "PNG", NULL};
// Names known by ImageGrab.py in the same order as the formats above
LPCSTR format_names[] = {"DIB", "DIB", "file", "PNG", NULL};

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've pushed a similar comment, that connects it clearly to the variable in ImageGrab.py.

radarhere and others added 2 commits September 29, 2026 17:31
Co-authored-by: Aarni Koskela <akx@iki.fi>
@radarhere
radarhere merged commit d363ad5 into python-pillow:main Sep 29, 2026
61 checks passed
@radarhere
radarhere deleted the grab branch September 29, 2026 10:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants