libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
{ "cpes": [ "cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*" ], "severity": "High" }