Executive brief
Pillow is a widely used Python library for opening, manipulating, and saving many different image file formats. A vulnerability was found where providing specifically formatted coordinate data (nested lists) to certain drawing functions can cause the application to crash or behave unexpectedly. This could lead to a denial-of-service condition for applications that process user-supplied image coordinates.
Technical details
A heap-based buffer overflow (CWE-122) exists in Pillow's coordinate unpacking logic. When nested lists are passed as coordinates to APIs like ImagePath.Path, ImageDraw.polygon, or ImageDraw.line, the library recursively unpacks them beyond the bounds of the allocated heap buffer. An attacker who can control the coordinate input to these functions could trigger a memory corruption, potentially leading to a crash or arbitrary code execution, though the reported CVSS focuses on availability impact. The issue was introduced in version 11.2.1 and is fixed in 12.2.0 by validating that coordinate lists contain exactly two numeric elements.
Affected products
- python-pillow Pillow >= 11.2.1, < 12.2.0
Timeline
- 2026-04-23: advisory: GitHub Security Advisory published
- 2026-05-09: disclosed: CVE published to NVD
- 2026-04-01: patched: Version 12.2.0 released