Home / Errors / decompression-bomb

DecompressionBombWarning and bomb errors

Pillow warns when an image is large enough to be a denial of service attack. Here is what the limit is and when to change it.

Image size exceeds limit, DecompressionBombWarning

What triggers it

Pillow warns above about 89 million pixels and raises DecompressionBombError above twice that. A small compressed file can expand into gigabytes of memory, which is the attack this guards against.

If the image is genuinely that big

from PIL import Image

Image.MAX_IMAGE_PIXELS = 300_000_000

Reasonable for scanned maps, satellite imagery, gigapixel panoramas and microscopy, where enormous files are normal. Set it to None to disable the check entirely, but only for files you produced yourself.

Never raise this on a server that accepts uploads from the public. The check is the only thing standing between a 2 KB file and your memory limit.

Checking the size before decoding

from PIL import Image

with Image.open(upload) as im:
    width, height = im.size

if width * height > 40_000_000:
    raise ValueError("image too large")

im = Image.open(upload)
im.load()

Image.open reads the header only, so you get the dimensions without decoding anything. That is the safe way to reject oversized uploads.

Keeping the warning quiet for one call

import warnings
from PIL import Image

with warnings.catch_warnings():
    warnings.simplefilter("ignore", Image.DecompressionBombWarning)
    im = Image.open(path)
    im.load()

Still stuck

The PIL to Pillow converter finds most of these automatically, and the other error pages cover the rest.