Python / Pillow
73 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-54058 | Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files) | HIGH | 8.3 | Jul 14, 2026 |
| CVE-2026-59197 | Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` | HIGH | 8.2 | Jul 14, 2026 |
| CVE-2026-59200 | Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() | HIGH | 7.5 | Jul 14, 2026 |
| CVE-2026-59198 | Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images | HIGH | 7.5 | Jul 14, 2026 |
| CVE-2026-59205 | Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch | HIGH | 7.5 | Jul 14, 2026 |
| CVE-2026-59203 | Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service | HIGH | 7.5 | Jul 14, 2026 |
| CVE-2026-59199 | Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow | HIGH | 7.5 | Jul 14, 2026 |
| CVE-2026-59204 | Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service | HIGH | 8.7 | Jul 14, 2026 |
| CVE-2026-55379 | Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading | HIGH | 7.5 | Jul 6, 2026 |
| CVE-2026-55380 | Pillow GdImageFile decompression bomb protection bypass | HIGH | 7.5 | Jul 6, 2026 |
| CVE-2026-54060 | Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()` | HIGH | 7.5 | Jul 6, 2026 |
| CVE-2026-54059 | Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading | HIGH | 7.5 | Jul 6, 2026 |
| CVE-2026-55798 | Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path | MEDIUM | 4.5 | Jul 6, 2026 |
| CVE-2026-42311 | Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow) | HIGH | 8.6 | May 9, 2026 |
| CVE-2026-42310 | Pillow: PDF Parsing Trailer Infinite Loop (DoS) | MEDIUM | 5.1 | May 9, 2026 |
| CVE-2026-42308 | Pillow: Integer overflow when processing fonts | MEDIUM | 5.1 | May 9, 2026 |
| CVE-2026-42309 | Pillow: Heap buffer overflow with nested list coordinates | MEDIUM | 5.1 | May 9, 2026 |
| CVE-2026-40192 | Pillow is vulnerable to a FITS GZIP decompression bomb | HIGH | 8.7 | Apr 15, 2026 |
| CVE-2026-25990 | Pillow has an out-of-bounds write when loading PSD images | HIGH | 8.6 | Feb 11, 2026 |
| CVE-2025-48379 | Pillow Vulnerable to Write Buffer Overflow on BCn encoding | HIGH | 7.1 | Jul 1, 2025 |
| CVE-2024-28219 | python-pillow: buffer overflow in _imagingcms.c | HIGH | 7.3 | Apr 3, 2024 |
| CVE-2023-50447 | pillow: Arbitrary Code Execution via the environment parameter | CRITICAL | 9.3 | Jan 19, 2024 |
| CVE-2023-44271 | python-pillow: uncontrolled resource consumption when textlength in an ImageDraw instance operates on a long text argument | HIGH | 8.7 | Nov 3, 2023 |
| CVE-2022-45199 | Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL. | HIGH | 8.7 | Nov 14, 2022 |
| CVE-2022-45198 | Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification). | HIGH | 8.7 | Nov 14, 2022 |
Showing 1 to 25 of 73 CVEs