Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

python-pillow — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting python-pillow. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates vulnerability data for the vendor python-pillow, focusing on software weaknesses and security flaws within the Pillow image processing library. It provides a comprehensive collection of identified security issues, covering the period from 2010 to 2024, ensuring that historical and recent threats are documented for thorough analysis. Users can leverage this resource to track vendor advisories and monitor how the python-pillow project responds to emerging security challenges. By reviewing the aggregated data, you can gain a deeper understanding of common weakness classes prevalent in this codebase, such as buffer overflows or path traversal errors, and see how they manifest in real-world scenarios. Additionally, the page allows you to look up the vulnerability history of specific products built on or dependent on python-pillow, offering insight into their long-term security posture. This structured approach helps security professionals, developers, and auditors assess risk exposure without sifting through unorganized reports. The information is organized to facilitate quick identification of patterns and trends, supporting informed decision-making during security reviews and compliance checks. Accessing this consolidated view saves time by presenting all relevant vulnerabilities in one location, reducing the effort required to maintain an up-to-date understanding of the library's security landscape. This resource serves as a centralized reference point for evaluating the impact of known flaws on systems utilizing python-pillow, enabling proactive mitigation strategies and better protection of digital assets against potential exploits.

Top products by python-pillow: Pillow
CVE IDTitleCVSSSeverityPublished
CVE-2026-54058 Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files) — PillowCWE-125--2026-07-14
CVE-2026-59197 Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` — PillowCWE-787 8.2 High2026-07-14
CVE-2026-59200 Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() — PillowCWE-400 7.5 High2026-07-14
CVE-2026-59198 Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images — PillowCWE-125 6.5 Medium2026-07-14
CVE-2026-59205 Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch — PillowCWE-787 7.5 High2026-07-14
CVE-2026-59203 Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service — PillowCWE-835 5.3 Medium2026-07-14
CVE-2026-59199 Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow — PillowCWE-190 7.5 High2026-07-14
CVE-2026-59204 Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service — PillowCWE-789--2026-07-14
CVE-2026-55379 Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading — PillowCWE-789 7.5 High2026-07-06
CVE-2026-55380 Pillow GdImageFile decompression bomb protection bypass — PillowCWE-789 7.5 High2026-07-06
CVE-2026-54060 Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()` — PillowCWE-789 7.5 High2026-07-06
CVE-2026-54059 Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading — PillowCWE-789 7.5 High2026-07-06
CVE-2026-55798 Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path — PillowCWE-78 4.5 Medium2026-07-06
CVE-2026-42311 Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow) — PillowCWE-190 7.8 -2026-05-09
CVE-2026-42310 Pillow: PDF Parsing Trailer Infinite Loop (DoS) — PillowCWE-835 5.5 -2026-05-09
CVE-2026-42308 Pillow: Integer overflow when processing fonts — PillowCWE-190 9.1 -2026-05-09
CVE-2026-42309 Pillow: Heap buffer overflow with nested list coordinates — PillowCWE-122 9.8 -2026-05-09
CVE-2026-40192 Pillow is vulnerable to a FITS GZIP decompression bomb — PillowCWE-770 8.7 High2026-04-15
CVE-2026-25990 Pillow has an out-of-bounds write when loading PSD images — PillowCWE-787 8.6 High2026-02-11
CVE-2025-48379 Pillow Vulnerable to Write Buffer Overflow on BCn encoding — PillowCWE-122 7.1 High2025-07-01

This page lists every published CVE security advisory associated with python-pillow. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.