« Volver al listado

Python

Python Pillow: vulnerabilidades y CVE

Python Pillow tiene 73 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE73
Últimos 12 meses19
Críticas10
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-59200Alta (7.5)0.66%—14 jul 2026
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed…
CVE-2026-59197Alta (8.2)0.58%—14 jul 2026
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls…
CVE-2026-54058Alta (8.3)0.68%—14 jul 2026
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller…
CVE-2026-59205Alta (7.5)0.66%—14 jul 2026
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not…
CVE-2026-59204Alta (8.7)0.66%—14 jul 2026
Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted…
CVE-2026-59203Alta (7.5)0.66%—14 jul 2026
Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause…
CVE-2026-59199Alta (7.5)0.66%—14 jul 2026
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(),…
CVE-2026-59198Alta (7.5)0.50%—14 jul 2026
Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be…
CVE-2026-55798Media (4.5)0.18%—6 jul 2026
Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to…
CVE-2026-55380Alta (7.5)0.64%—6 jul 2026
Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(),…
CVE-2026-55379Alta (7.5)0.65%—6 jul 2026
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling…
CVE-2026-54060Alta (7.5)0.64%—6 jul 2026
Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling…
CVE-2026-54059Alta (7.5)0.64%—6 jul 2026
Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling…
CVE-2026-42311Alta (8.6)0.22%—9 may 2026
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue…
CVE-2026-42310Media (5.1)0.18%—9 may 2026
Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application…
CVE-2026-42309Media (5.1)0.18%—9 may 2026
Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and…
CVE-2026-42308Media (5.1)0.16%—9 may 2026
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This…
CVE-2026-40192Alta (8.7)0.87%—15 abr 2026
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially…
CVE-2026-25990Alta (8.6)0.45%—11 feb 2026
Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.
CVE-2025-48379Media (5.5)0.30%—1 jul 2025
Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into…
CVE-2024-28219Media (5.9)1.00%—3 abr 2024
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
CVE-2023-50447Alta (8.1)1.7%—19 ene 2024
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
CVE-2023-44271Alta (7.5)1.1%—3 nov 2023
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs…
CVE-2022-45199Alta (7.5)1.2%—14 nov 2022
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
CVE-2022-45198Alta (7.5)1.3%—14 nov 2022
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
CVE-2022-30595Crítica (9.8)2.3%—25 may 2022
libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
CVE-2022-24303Crítica (9.1)2.7%—28 mar 2022
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
CVE-2022-22817Crítica (9.8)3.3%—10 ene 2022
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
CVE-2022-22816Media (6.5)1.9%—10 ene 2022
path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.
CVE-2022-22815Media (6.5)2.6%—10 ene 2022
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.

Otros productos de Python