Vulnerabilities in python-pillow

20 results
Vexday analysis

A biblioteca Python Pillow apresenta um perfil de risco moderado com 20 vulnerabilidades catalogadas, das quais 17 foram publicadas nos últimos 90 dias, indicando descobertas recentes aceleradas. Nenhuma vulnerabilidade está sob ataque ativo (KEV) e não há casos críticos documentados, mas a fraqueza dominante CWE-787 (out-of-bounds write) sugere potencial para exploração com impacto significativo em sistemas que processam imagens não confiáveis. A concentração temporal das divulgações recomenda monitoramento ativo e planejamento de patches prioritários.

CVE-2026-40192HIGHPillow is vulnerable to a FITS GZIP decompression bombEPSS 0.7%CVE-2026-54058HIGHPillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)EPSS 0.5%CVE-2026-59197HIGHPillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`EPSS 0.4%CVE-2026-55379HIGHPillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loadingEPSS 0.4%CVE-2026-55380HIGHPillow GdImageFile decompression bomb protection bypassEPSS 0.4%CVE-2026-54060HIGHPillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`EPSS 0.4%CVE-2026-54059HIGHPillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loadingEPSS 0.4%CVE-2026-59203MEDIUMPillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of serviceEPSS 0.4%CVE-2026-59204HIGHPillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of serviceEPSS 0.4%CVE-2026-59200HIGHPillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()EPSS 0.4%CVE-2026-59199HIGHPillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflowEPSS 0.4%CVE-2026-59205HIGHPillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatchEPSS 0.4%CVE-2026-25990HIGHPillow has an out-of-bounds write when loading PSD imagesEPSS 0.4%CVE-2026-59198MEDIUMPillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated imagesEPSS 0.3%CVE-2025-48379HIGHPillow Vulnerable to Write Buffer Overflow on BCn encodingEPSS 0.3%CVE-2026-55798MEDIUMPillow: WindowsViewer.get_command() OS command injection via unescaped shell pathEPSS 0.2%CVE-2026-42311HIGHPillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)EPSS 0.1%CVE-2026-42309MEDIUMPillow: Heap buffer overflow with nested list coordinatesEPSS 0.1%CVE-2026-42310MEDIUMPillow: PDF Parsing Trailer Infinite Loop (DoS)EPSS 0.1%CVE-2026-42308MEDIUMPillow: Integer overflow when processing fontsEPSS 0.1%