CVE Tools

Python-pillow

13 CVEs tracked since 2026. Since Jul 2026, none of them reached CISA KEV.

Python-pillow CVEs per month

Jul 2026 to Jul 2026. Point at a month, or focus the strip and use the arrow keys.
Python-pillow CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-07130

Products

The products that kept showing up in Python-pillow's monthly top three, with their CVEs summed over those months.

  1. Pillow131 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Python-pillow.

  1. CVE-2026-54058Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)9.1
  2. CVE-2026-59197Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`8.2
  3. CVE-2026-59200Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()7.5
  4. CVE-2026-59198Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images6.5
  5. CVE-2026-59205Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch7.5
  6. CVE-2026-59203Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service5.3
  7. CVE-2026-59199Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow7.5
  8. CVE-2026-59204Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service7.5
  9. CVE-2026-55379Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading7.5
  10. CVE-2026-55380Pillow GdImageFile decompression bomb protection bypass7.5
  11. CVE-2026-54060Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`7.5
  12. CVE-2026-54059Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading7.5
  13. CVE-2026-55798Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path4.5
  14. CVE-2026-42311Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)7.8
  15. CVE-2026-42310Pillow: PDF Parsing Trailer Infinite Loop (DoS)5.5

The record

Peak rank
#106 in Jul 2026
Busiest month shown
Jul 2026, 13 CVEs
Months with a KEV entry
0 since Jul 2026
Monthly snapshots
1 since 2026
Python-pillow's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store