pillow has 8 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 4 in the last 90 days against 2 in the 90 before. The busiest recent month was July 2026 with 4. The median CVSS is 6.0 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.0
- Publish → KEV
- —
- Last 90 days
- 4 prev 2
Weakness classes
Products
- pillow 8
Worst active — by depth score
CVE-2023-50447High· 8.1Arbitrary Code Execution in Pillow45CVE-2026-54059High· 7.5Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF f…41CVE-2024-28219Medium· 6.7Pillow buffer overflow vulnerability37CVE-2026-59198Medium· 6.5Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images36CVE-2026-42310Medium· 5.5Pillow has a PDF Parsing Trailer Infinite Loop (DoS)30
pillow vulnerabilities
CVEs affecting pillow, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-59198Medium· 6.5Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
CVE-2026-59203Medium· 5.3Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
CVE-2026-55798Medium· 4.5Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
CVE-2026-54059High· 7.5Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF f…
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
CVE-2026-42310Medium· 5.5Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
CVE-2026-42309Medium· 5.5Pillow has a heap buffer overflow with nested list coordinates
Pillow has a heap buffer overflow with nested list coordinates
CVE-2024-28219Medium· 6.7Pillow buffer overflow vulnerability
Pillow buffer overflow vulnerability
CVE-2023-50447High· 8.1Arbitrary Code Execution in Pillow
Arbitrary Code Execution in Pillow