CVE-2023-50447High· 8.1▾ TwilightArbitrary Code Execution in Pillow
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.7%
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
pillow < 10.2.0Upgrade to a patched release:
pillow 10.2.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59198Medium· 6.5Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
CVE-2026-59203Medium· 5.3Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
CVE-2026-55798Medium· 4.5Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
CVE-2026-54059High· 7.5Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF f…
CVE-2026-42310Medium· 5.5Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
CVE-2026-42309Medium· 5.5Pillow has a heap buffer overflow with nested list coordinates