libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
libImaging/SgiRleDecode.c
{ "last_known_affected_version_range": "<= 6.2.1" }