Image size exceeds limit, DecompressionBombWarning
Pillow warns above about 89 million pixels and raises DecompressionBombError above twice that. A small compressed file can expand into gigabytes of memory, which is the attack this guards against.
from PIL import Image
Image.MAX_IMAGE_PIXELS = 300_000_000
Reasonable for scanned maps, satellite imagery, gigapixel panoramas and microscopy, where enormous files are normal. Set it to None to disable the check entirely, but only for files you produced yourself.
from PIL import Image
with Image.open(upload) as im:
width, height = im.size
if width * height > 40_000_000:
raise ValueError("image too large")
im = Image.open(upload)
im.load()
Image.open reads the header only, so you get the dimensions without decoding anything. That is the safe way to reject oversized uploads.
import warnings
from PIL import Image
with warnings.catch_warnings():
warnings.simplefilter("ignore", Image.DecompressionBombWarning)
im = Image.open(path)
im.load()
The PIL to Pillow converter finds most of these automatically, and the other error pages cover the rest.