python-pillow Pillow是python-pillow的图像处理库。 python-pillow Pillow 12.3.0之前版本存在缓冲区错误漏洞,该漏洞源于加载未压缩的McIdas AREA图像时,攻击者控制的标头字可将行跨度设置为小于自然行宽度,导致像素访问超出映射区域并泄露相邻进程内存或故障。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| python-pillow | Pillow | < 12.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| python-pillow | Pillow | < 12.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59197 | 8.2 HIGH | Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow i |
| CVE-2026-59199 | 7.5 HIGH | Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate ov |
| CVE-2026-59205 | 7.5 HIGH | Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode |
| CVE-2026-59200 | 7.5 HIGH | Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() |
| CVE-2026-59198 | 6.5 MEDIUM | Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated ima |
| CVE-2026-59203 | 5.3 MEDIUM | Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of ser |
| CVE-2026-59204 | Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial o |
No comments yet