CVE Tools

Pillow

76 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Pillow, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Pillow CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Pillow CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-071
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-030
2026-041
2026-054
2026-060
2026-0713
2026-080
2026-090

Severity

How the 76 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1216%
  • High3649%
  • Medium2534%
  • Low11%

Latest CVEs

The 15 most recently published vulnerabilities affecting Pillow.

  1. CVE-2026-54058Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)9.1
  2. CVE-2026-59197Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`8.2
  3. CVE-2026-59200Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()7.5
  4. CVE-2026-59198Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images6.5
  5. CVE-2026-59205Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch7.5
  6. CVE-2026-59203Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service5.3
  7. CVE-2026-59199Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow7.5
  8. CVE-2026-59204Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service7.5
  9. CVE-2026-55379Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading7.5
  10. CVE-2026-55380Pillow GdImageFile decompression bomb protection bypass7.5
  11. CVE-2026-54060Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`7.5
  12. CVE-2026-54059Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading7.5
  13. CVE-2026-55798Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path4.5
  14. CVE-2026-42311Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)7.8
  15. CVE-2026-42310Pillow: PDF Parsing Trailer Infinite Loop (DoS)5.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store