📦

pillow

Vendor: python

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 15 Remote Access
Total CVEs 145 Total Indexed
Avg. EPSS 1.95% Exploit Prob.
Latest CVE CVE-2026-59200 Jul 14

Security Vulnerability Index

Page 5 / 15
7.5 CVSS

An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.

EPSS: 2.37%
9.8 CVSS

An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.

EPSS: 2.28%
7.5 CVSS

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.

EPSS: 3.07%
7.5 CVSS

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.

EPSS: 4.85%
7.5 CVSS

Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.

EPSS: 3.17%
5.4 CVSS

In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.

EPSS: 1.57%
8.8 CVSS

In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.

EPSS: 1.79%
7.1 CVSS

In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.

EPSS: 1.50%
8.1 CVSS

In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.

EPSS: 2.51%
5.5 CVSS

In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.

EPSS: 1.42%