CVE-2026-59204High· 7.5▾ TwilightA flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted JPEG2000 image file. Due to incorrect calculation of memory requirements for image tiles, processing …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
Last analysed / modified upstream
A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit this vulnerability by providing a specially crafted JPEG2000 image file. Due to incorrect calculation of memory requirements for image tiles, processing this file can lead to excessive memory consumption, resulting in a denial of service (DoS) through out-of-memory failures.
Pillow: Pillow: Denial of Service via crafted JPEG2000 image — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For more information visit https://access.redhat.com/errata/RHSA-2026:61628 https://access.redhat.com/errata/RHSA-2026:61628 For more information visit https://access.redhat.com/errata/RHSA-2026:61627 https://access.redhat.com/errata/RHSA-2026:61627 For more information visit https://access.redhat.com/errata/RHSA-2026:61629 https://access.redhat.com/errata/RHSA-2026:61629
Workarounds / mitigations:
For services that do process JPEG2000, set memory limits on the process or container (LimitAS= in systemd, or memory limits in Kubernetes/Podman) so a crafted image can only crash the worker, not the whole host. Add automatic restarts (Restart=always in systemd, or container restart policies) so the service recovers from OOM kills without someone having to intervene.
Affected packages:
pillow >= 8.2.0, < 12.3.0Patched in:
pillow 12.3.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59200High· 7.5Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)
CVE-2026-55379High· 7.5python-pillow: Pillow: Denial of Service via crafted BDF font file (CVE-2026-55379)
CVE-2026-54283High· 7.5starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS (CVE-2026-54283)
CVE-2026-59885High· 7.5pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER (CVE-2026-59885)
CVE-2026-59197High· 8.2Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)
CVE-2026-54058Critical· 9.1Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)