Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Pillow — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in Pillow, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Pillow, an open-source Python imaging library, categorized by specific weakness types and associated security tags. The collection gathers historical security advisories for this product, covering its entire known vulnerability history from the earliest recorded defects to the most recent patches. Readers can use this interface to track the vendor’s advisory releases, analyze the prevalence of specific weakness classes within the codebase, and review the complete vulnerability timeline for Pillow.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-54058 Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files) CWE-125 - - 2026-07-14
CVE-2026-59197 Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` CWE-787 8.2 High 2026-07-14
CVE-2026-59200 Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() CWE-400 7.5 High 2026-07-14
CVE-2026-59198 Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images CWE-125 6.5 Medium 2026-07-14
CVE-2026-59205 Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch CWE-787 7.5 High 2026-07-14
CVE-2026-59203 Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service CWE-835 5.3 Medium 2026-07-14
CVE-2026-59199 Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow CWE-190 7.5 High 2026-07-14
CVE-2026-59204 Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service CWE-789 - - 2026-07-14
CVE-2026-55379 Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading CWE-789 7.5 High 2026-07-06
CVE-2026-55380 Pillow GdImageFile decompression bomb protection bypass CWE-789 7.5 High 2026-07-06
CVE-2026-54060 Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()` CWE-789 7.5 High 2026-07-06
CVE-2026-54059 Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading CWE-789 7.5 High 2026-07-06
CVE-2026-55798 Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path CWE-78 4.5 Medium 2026-07-06
CVE-2026-42311 Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow) CWE-190 7.8 - 2026-05-09
CVE-2026-42310 Pillow: PDF Parsing Trailer Infinite Loop (DoS) CWE-835 5.5 - 2026-05-09
CVE-2026-42308 Pillow: Integer overflow when processing fonts CWE-190 9.1 - 2026-05-09
CVE-2026-42309 Pillow: Heap buffer overflow with nested list coordinates CWE-122 9.8 - 2026-05-09
CVE-2026-40192 Pillow is vulnerable to a FITS GZIP decompression bomb CWE-770 8.7 High 2026-04-15
CVE-2026-25990 Pillow has an out-of-bounds write when loading PSD images CWE-787 8.6 High 2026-02-11
CVE-2025-48379 Pillow Vulnerable to Write Buffer Overflow on BCn encoding CWE-122 7.1 High 2025-07-01
CVE-2021-23437 Regular Expression Denial of Service (ReDoS) 7.5 High 2021-09-03

All 21 known CVE vulnerabilities affecting Pillow with full Chinese analysis, references, and POCs where available.