CVE-2026-59197High· 8.2▾ TwilightA flaw was found in Pillow prior to 12.3.0. The public RankFilter API can trigger a native heap out-of-bounds write when given a very large odd filter size. ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before ra…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
0.4% → 0.4%
Last analysed / modified upstream
A flaw was found in Pillow prior to 12.3.0. The public RankFilter API can trigger a native heap out-of-bounds write when given a very large odd filter size. ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation, and ImagingExpand() computes output dimensions with unchecked signed integer arithmetic. This can lead to denial of service and limited integrity impact via heap corruption.
Pillow: Pillow: Native heap out-of-bounds write — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50319 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For detailed instructions how to apply this update, refer to:
https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:50223 For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50336
Affected packages:
pillow < 12.3.0Patched in:
pillow 12.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59199High· 7.5Pillow: Pillow: Denial of Service via out-of-bounds write in image processing (CVE-2026-59199)
CVE-2026-59885High· 7.5pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59885)
CVE-2026-59200High· 7.5Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)
CVE-2026-59204High· 7.5Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)
CVE-2026-54058Critical· 9.1Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)
CVE-2026-59205High· 7.5Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API (CVE-2026-59205)