---
id: CVE-2026-59197
title: 'Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)'
summary: >-
  A flaw was found in Pillow prior to 12.3.0. The public RankFilter API can
  trigger a native heap out-of-bounds write when given a very large odd filter
  size. ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2)
  before ra…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'
cvssSource: vendor
cwe:
  - CWE-787
  - CWE-190
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - exploit_intelligence
  - lightspeed_core
  - openshift_lightspeed
  - ai_inference_server
  - ansible_automation_platform 2
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - satellite 6
  - ansible_automation_platform_2_5_for_rhel 8
  - satellite_6_16_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - satellite_6_16_for_rhel 9
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_4
  - enterprise_linux_appstream_eus_extension_v_8_4
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_crb_v_8
  - ai_inference_server 3.4
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - openshift_ai 3.4
  - quay 3.10
  - quay 3.12
  - quay 3.15
  - quay 3.16
  - quay 3.9
patched:
  - ansible_automation_platform_2_5_for_rhel 8
  - satellite_6_16_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - satellite_6_16_for_rhel 9
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_4
  - enterprise_linux_appstream_eus_extension_v_8_4
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_eus_extension_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_crb_v_8
  - ai_inference_server 3.4
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - openshift_ai 3.4
  - quay 3.10
  - quay 3.12
  - quay 3.15
  - quay 3.16
  - quay 3.9
published: '2026-07-14'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T16:32:45+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59197.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59197.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59197'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2500043'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59197'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59197'
  - url: >-
      https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1
  - url: 'https://github.com/python-pillow/Pillow/pull/9695'
  - url: 'https://github.com/python-pillow/Pillow/releases/tag/12.3.0'
  - url: >-
      https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr
  - url: 'https://access.redhat.com/errata/RHSA-2026:50319'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50223'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50336'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48021'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52551'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54528'
  - url: 'https://access.redhat.com/errata/RHSA-2026:54417'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69468'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69466'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69467'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69469'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69464'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50479'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50340'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:53520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:52968'
  - url: 'https://access.redhat.com/errata/RHSA-2026:48933'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69255'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50931'
  - url: 'https://github.com/python-pillow/Pillow'
  - url: 'https://github.com/advisories/GHSA-xj96-63gp-2gmr'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - ghsa
epss: 0.00445
epssPercentile: 0.38003
aliases:
  - GHSA-xj96-63gp-2gmr
  - BIT-pillow-2026-59197
  - PYSEC-2026-3454
ecosystem: pip
ingestedAt: '2026-07-20T23:44:02.535Z'
---

## Overview

A flaw was found in Pillow prior to 12.3.0. The public RankFilter API can trigger a native heap out-of-bounds write when given a very large odd filter size. ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation, and ImagingExpand() computes output dimensions with unchecked signed integer arithmetic. This can lead to denial of service and limited integrity impact via heap corruption.

## Vendor advisories

- **RHSA-2026:50319** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50319)
- **RHSA-2026:50223** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50223)
- **RHSA-2026:50336** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50336)
- **RHSA-2026:48021** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48021)
- **RHSA-2026:52551** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52551)
- **RHSA-2026:54528** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-08-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:54528)
- **RHSA-2026:54417** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54417)
- **RHSA-2026:69468** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69468)
- **RHSA-2026:69466** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69466)
- **RHSA-2026:69467** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69467)
- **RHSA-2026:69469** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69469)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, … · no fix planned: Red Hat AI Inference Server, Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59197.json)
- **RHSA-2026:50479** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50479)
- **RHSA-2026:50340** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50340)
- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **RHSA-2026:53520** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53520)

**Pillow: Pillow: Native heap out-of-bounds write** — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-21.

Affected:

- Exploit Intelligence
- Lightspeed Core
- OpenShift Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6

Fixed:

- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Satellite 6.16 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Satellite 6.16 for RHEL 9
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream AUS (v.8.4)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
- Red Hat Enterprise Linux AppStream AUS (v.8.6)
- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)
- Red Hat Enterprise Linux AppStream E4S (v.8.8)
- Red Hat Enterprise Linux AppStream TUS (v.8.8)
- Red Hat Enterprise Linux CRB (v. 8)
- Red Hat AI Inference Server 3.4
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat OpenShift AI 3.4
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.15
- Red Hat Quay 3.16
- Red Hat Quay 3.9

No fix planned:

- Red Hat AI Inference Server
- Exploit Intelligence
- Lightspeed Core
- OpenShift Lightspeed
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6

Not affected:

- Red Hat Ansible Automation Platform 2.6 for RHEL 10
- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Satellite 6.16 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Satellite 6.16 for RHEL 9
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat OpenShift AI 3.4
- Red Hat Quay 3.10

## Remediation

For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50319
Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For detailed instructions how to apply this update, refer to:

https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:50223
For details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50336

## Package advisory (CVE-2026-59197)

Affected packages:

- `pillow < 12.3.0`

Patched in:

- `pillow 12.3.0`

Source: https://osv.dev/vulnerability/GHSA-xj96-63gp-2gmr
