VulnSea

pillow vulnerabilities

CVEs whose affected-version data names the pillow package (pip, rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

12 CVEsRSS

CVE-2026-59198Medium· 6.5
2mo ago

Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

Sunlitpillow · pillowEPSS 0.33%via OSV
CVE-2026-59203Medium· 5.3
2mo ago

Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service

Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service

Sunlitpillow · pillowEPSS 0.66%via OSV
CVE-2026-55798Medium· 4.5
2mo ago

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

Sunlitpillow · pillowEPSS 0.18%via OSV
CVE-2026-54059High· 7.5
2mo ago

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF f…

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

Twilightpillow · pillowEPSS 0.41%via OSV
CVE-2026-42310Medium· 5.5
4mo ago

Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

Sunlitpillow · pillowEPSS 0.13%via OSV
CVE-2026-42309Medium· 5.5
4mo ago

Pillow has a heap buffer overflow with nested list coordinates

Pillow has a heap buffer overflow with nested list coordinates

Sunlitpillow · pillowEPSS 0.13%via OSV
CVE-2026-40192High· 7.5
5mo ago

Pillow is a Python imaging library

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file coul…

Twilightpython · pillowEPSS 0.67%via NVD
CVE-2026-25990High· 7.5
7mo ago

Pillow is a Python imaging library

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

Twilightpython · pillowEPSS 0.37%via NVD
CVE-2025-48379High· 7.1
1y ago

Pillow is a Python imaging library

Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without …

Twilightpython · pillowEPSS 0.30%via NVD
CVE-2024-28219Medium· 6.7
2y ago

Pillow buffer overflow vulnerability

Pillow buffer overflow vulnerability

Sunlitpillow · pillowEPSS 1.00%via OSV
CVE-2023-50447High· 8.1
2y ago

Arbitrary Code Execution in Pillow

Arbitrary Code Execution in Pillow

Twilightpillow · pillowEPSS 1.7%via OSV
CVE-2023-4863High· 8.8CISA KEV0dayPoC
3y ago

libwebp: OOB write in BuildHuffmanTable

libwebp: OOB write in BuildHuffmanTable

Abyssallibwebp-sys2 · libwebp-sys2EPSS 100%via OSV
pillow vulnerabilities (CVEs) · VulnSea