pillow vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-59205Highpillow: Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatchCVE-2026-59204Highpillow: Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of serviceCVE-2026-59203Mediumpillow: Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of serviceCVE-2026-59200HighPillow: Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()CVE-2026-59199HighPillow: Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflowCVE-2026-59198MediumPillow: Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated imagesCVE-2026-59197HighPillow: Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`CVE-2026-55798MediumPillow: Pillow: WindowsViewer.get_command() OS command injection via unescaped shell pathCVE-2026-55380Highpillow: Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`CVE-2026-55379Highpillow: Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loadingCVE-2026-54060Highpillow: Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`CVE-2026-54059Highpillow: Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF…CVE-2026-54058Highpillow: Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)CVE-2026-42311Highpillow: Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)CVE-2026-42310Mediumpillow: Pillow has a PDF Parsing Trailer Infinite Loop (DoS)CVE-2026-42308Mediumpillow: Pillow has an integer overflow when processing fontsCVE-2026-42309Mediumpillow: Pillow has a heap buffer overflow with nested list coordinatesCVE-2026-40192Highpillow: FITS GZIP decompression bomb in PillowCVE-2026-25990Highpillow: Pillow affected by out-of-bounds write when loading PSD imagesCVE-2025-48379Highpillow: Pillow vulnerability can cause write buffer overflow on BCn encodingCVE-2024-28219Highpillow: Pillow buffer overflow vulnerabilityCVE-2023-50447CriticalPillow: Arbitrary Code Execution in PillowCVE-2023-44271Highpillow: Pillow Denial of Service vulnerabilityCVE-2023-4863Highlibwebp-sys2: libwebp: OOB write in BuildHuffmanTableCVE-2022-45198Highpillow: Pillow vulnerable to Data Amplification attack.

Stop the waste.
Protect your environment with Kodem.