python-pillow
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting python-pillow.
- CVE-2026-54058Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)9.1
- CVE-2026-59197Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`8.2
- CVE-2026-59200Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()7.5
- CVE-2026-59198Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images6.5
- CVE-2026-59205Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch7.5
- CVE-2026-59203Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service5.3
- CVE-2026-59199Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow7.5
- CVE-2026-59204Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service7.5
- CVE-2026-55379Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading7.5
- CVE-2026-55380Pillow GdImageFile decompression bomb protection bypass7.5
- CVE-2026-54060Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`7.5
- CVE-2026-54059Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading7.5
- CVE-2026-55798Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path4.5
- CVE-2026-42311Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)7.8
- CVE-2026-42310Pillow: PDF Parsing Trailer Infinite Loop (DoS)5.5