python-pillow Pillow是python-pillow的图像处理库。 python-pillow Pillow存在资源管理错误漏洞,该漏洞源于在src/libImaging/Jpeg2KDecode.c中对total_component_width的处理不当,其在JPEG2000图像的每个平铺中累加而非重新计算,导致解码时出现大量瞬态内存使用并触发内存不足。以下版本受到影响:8.2.0版本、8.3.0版本、8.3.1版本、8.3.2版本、8.4.0版本、9.0.0版本、9.0.1版本、9.1
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| python-pillow | Pillow | >= 8.2.0, < 12.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| python-pillow | Pillow | >= 8.2.0, < 12.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59197 | 8.2 HIGH | Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow i |
| CVE-2026-59199 | 7.5 HIGH | Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate ov |
| CVE-2026-59205 | 7.5 HIGH | Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode |
| CVE-2026-59200 | 7.5 HIGH | Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() |
| CVE-2026-59198 | 6.5 MEDIUM | Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated ima |
| CVE-2026-59203 | 5.3 MEDIUM | Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of ser |
| CVE-2026-54058 | Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIda |
No comments yet