Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Pillow — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in Pillow, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security vulnerabilities associated with Pillow, a popular Python Imaging Library maintained by the Python Software Foundation. It focuses specifically on Common Weakness Enumeration (CWE) classified issues, including buffer overflows, use-after-free errors, and improper input validation flaws that could lead to denial of service or remote code execution. The content here collects data regarding known vulnerabilities discovered in various releases of the Pillow software package, covering a time range from its initial public releases up to the most recent updates. By reviewing this consolidated information, users can effectively track vendor security advisories issued by the Pillow maintainers, gain a deeper understanding of specific weakness classes prevalent in image processing libraries, and look up the complete vulnerability history of the product to assess risk exposure. This resource is designed for developers, security analysts, and system administrators who need to evaluate the integrity of their software dependencies without sifting through scattered sources. The aggregated data highlights patterns in coding errors and configuration mistakes, offering valuable insights into the evolution of security practices within the project. Users are encouraged to use this page as a reference point for patch management and risk assessment, ensuring that they remain informed about potential threats affecting their deployment environments. The information presented is derived from official reports, public disclosures, and community submissions, ensuring accuracy and relevance for technical audiences seeking detailed vulnerability intelligence.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-54058 Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files) CWE-125--2026-07-14
CVE-2026-59197 Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` CWE-787 8.2 High2026-07-14
CVE-2026-59200 Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() CWE-400 7.5 High2026-07-14
CVE-2026-59198 Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images CWE-125 6.5 Medium2026-07-14
CVE-2026-59205 Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch CWE-787 7.5 High2026-07-14
CVE-2026-59203 Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service CWE-835 5.3 Medium2026-07-14
CVE-2026-59199 Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow CWE-190 7.5 High2026-07-14
CVE-2026-59204 Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service CWE-789--2026-07-14
CVE-2026-55379 Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading CWE-789 7.5 High2026-07-06
CVE-2026-55380 Pillow GdImageFile decompression bomb protection bypass CWE-789 7.5 High2026-07-06
CVE-2026-54060 Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()` CWE-789 7.5 High2026-07-06
CVE-2026-54059 Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading CWE-789 7.5 High2026-07-06
CVE-2026-55798 Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path CWE-78 4.5 Medium2026-07-06
CVE-2026-42311 Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow) CWE-190 7.8 -2026-05-09
CVE-2026-42310 Pillow: PDF Parsing Trailer Infinite Loop (DoS) CWE-835 5.5 -2026-05-09
CVE-2026-42308 Pillow: Integer overflow when processing fonts CWE-190 9.1 -2026-05-09
CVE-2026-42309 Pillow: Heap buffer overflow with nested list coordinates CWE-122 9.8 -2026-05-09
CVE-2026-40192 Pillow is vulnerable to a FITS GZIP decompression bomb CWE-770 8.7 High2026-04-15
CVE-2026-25990 Pillow has an out-of-bounds write when loading PSD images CWE-787 8.6 High2026-02-11
CVE-2025-48379 Pillow Vulnerable to Write Buffer Overflow on BCn encoding CWE-122 7.1 High2025-07-01
CVE-2021-23437 Regular Expression Denial of Service (ReDoS) 7.5 High2021-09-03

All 21 known CVE vulnerabilities affecting Pillow with full Chinese analysis, references, and POCs where available.