Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3496
  • PyPI/pillow
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service 23 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-3495
  • PyPI/pillow
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() 23 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-3494
  • PyPI/pillow
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images 23 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3493
  • PyPI/pillow
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files) 23 Jul
  • Fix available
  • Severity - 8.3 (High)
GHSA-9hw9-ch79-4vh6
  • PyPI/pillow
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch 20 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-vjc4-5qp5-m44j
  • PyPI/pillow
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service 20 Jul
  • Fix available
  • Severity - 8.7 (High)
GHSA-pg7v-jwj7-p798
  • PyPI/pillow
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service 20 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-jjj6-mw9f-p565
  • PyPI/pillow
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode() 20 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-6r8x-57c9-28j4
  • PyPI/pillow
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow 20 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-fj7v-r99m-22gq
  • PyPI/pillow
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images 20 Jul
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-xj96-63gp-2gmr
  • PyPI/pillow
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` 20 Jul
  • Fix available
  • Severity - 8.2 (High)
GHSA-4x4j-2g7c-83w6
  • PyPI/pillow
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path 20 Jul
  • Fix available
  • Severity - 4.5 (Medium)
GHSA-phj9-mv4w-65pm
  • PyPI/pillow
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()` 20 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-45hq-cxwh-f6vc
  • PyPI/pillow
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading 20 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-5x94-69rx-g8h2
  • PyPI/pillow
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()` 20 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-8v84-f9pq-wr9x
  • PyPI/pillow
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading 20 Jul
  • Fix available
  • Severity - 7.5 (High)