Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

python-pillow — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting python-pillow. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the vendor python-pillow, focusing on software weakness categories and product-specific defects. It collects a range of issues, including memory corruption, image processing flaws, and denial-of-service conditions, covering advisories published across recent years. Readers can use this resource to track the vendor’s security advisories, analyze patterns within a specific weakness class, and review the complete vulnerability history for the Pillow image processing library. The entries provide structured data on affected versions, impact severity, and remediation details, enabling technical teams to assess risk exposure and prioritize patching. This collection serves as a centralized reference for developers, security analysts, and system administrators maintaining Python-based imaging workloads. By consolidating disparate security reports into a single view, it supports trend analysis and historical comparison across multiple release cycles.

Top products by python-pillow: Pillow
CVE ID Title CVSS Severity Published
CVE-2026-54058 Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files) — Pillow CWE-125 - - 2026-07-14
CVE-2026-59197 Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` — Pillow CWE-787 8.2 High 2026-07-14
CVE-2026-59200 Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() — Pillow CWE-400 7.5 High 2026-07-14
CVE-2026-59198 Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images — Pillow CWE-125 6.5 Medium 2026-07-14
CVE-2026-59205 Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch — Pillow CWE-787 7.5 High 2026-07-14
CVE-2026-59203 Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service — Pillow CWE-835 5.3 Medium 2026-07-14
CVE-2026-59199 Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow — Pillow CWE-190 7.5 High 2026-07-14
CVE-2026-59204 Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service — Pillow CWE-789 - - 2026-07-14
CVE-2026-55379 Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading — Pillow CWE-789 7.5 High 2026-07-06
CVE-2026-55380 Pillow GdImageFile decompression bomb protection bypass — Pillow CWE-789 7.5 High 2026-07-06
CVE-2026-54060 Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()` — Pillow CWE-789 7.5 High 2026-07-06
CVE-2026-54059 Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading — Pillow CWE-789 7.5 High 2026-07-06
CVE-2026-55798 Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path — Pillow CWE-78 4.5 Medium 2026-07-06
CVE-2026-42311 Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow) — Pillow CWE-190 7.8 - 2026-05-09
CVE-2026-42310 Pillow: PDF Parsing Trailer Infinite Loop (DoS) — Pillow CWE-835 5.5 - 2026-05-09
CVE-2026-42308 Pillow: Integer overflow when processing fonts — Pillow CWE-190 9.1 - 2026-05-09
CVE-2026-42309 Pillow: Heap buffer overflow with nested list coordinates — Pillow CWE-122 9.8 - 2026-05-09
CVE-2026-40192 Pillow is vulnerable to a FITS GZIP decompression bomb — Pillow CWE-770 8.7 High 2026-04-15
CVE-2026-25990 Pillow has an out-of-bounds write when loading PSD images — Pillow CWE-787 8.6 High 2026-02-11
CVE-2025-48379 Pillow Vulnerable to Write Buffer Overflow on BCn encoding — Pillow CWE-122 7.1 High 2025-07-01

This page lists every published CVE security advisory associated with python-pillow. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.