In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2020-35655.json"