Junglewise Threat Intelligence

CVE-2026-59204: python-pillow Pillow denial of service in JPEG2000 decoding

CVE-2026-59204 · Severity: high · CVSS 4 · Published 2026-07-14

Technologies: pillow (PyPI). Vendors: PyPI.

Executive brief

Pillow, a widely used Python library for image processing, is vulnerable to a denial-of-service attack when processing certain JPEG2000 images. An attacker can provide a specially crafted image file that causes the library to consume excessive amounts of memory during decoding. This can lead to application crashes or system instability, potentially disrupting services that allow users to upload or process images.

Technical details

A resource exhaustion vulnerability exists in Pillow's JPEG2000 decoding logic within `src/libImaging/Jpeg2KDecode.c`. The variable `total_component_width` is incorrectly accumulated across all tiles in an image rather than being reset per tile. This accumulated value is used to calculate `tile_bytes`, which subsequently dictates the size of a `realloc` operation for `state->buffer`. An attacker can provide a JPEG2000 image with numerous tiles to force transient memory usage up to the size of the full decompressed image even for small tiles, leading to out-of-memory (OOM) failures. This is a denial-of-service vulnerability (CWE-770/CWE-789) and is patched in version 12.3.0.

Affected products

  • Python Pillow >= 8.2.0, < 12.3.0

Timeline

  • 2026-07-07: disclosed
  • 2026-07-14: advisory: NVD publication date
  • 2026-07-20: patched: GitHub Advisory reviewed/updated

References

Related threats