Executive brief
Pillow, a popular Python library for image processing, contains a vulnerability in its color management system. An attacker can provide a specially crafted image that causes the software to write data beyond its intended memory boundaries. This can lead to a service crash or potentially allow an attacker to gain further control over the system.
Technical details
A heap out-of-bounds write exists in Pillow's ImageCms extension due to insufficient validation of image modes in the `ImageCmsTransform.apply()` method. When a caller provides an `imOut` image with a mode (e.g., 'L', 1 byte per pixel) that is smaller than the transform's expected output mode (e.g., 'RGBA', 4 bytes per pixel), the underlying LittleCMS `cmsDoTransform` function writes more data than the destination buffer can hold. This occurs because the C wrapper `pyCMSdoTransform` in `src/_imagingcms.c` only verifies image dimensions but not pixel depth. An attacker who can control the transform parameters or the output image object can achieve controlled heap corruption, as source pixels influence the bytes written out of bounds. The issue is fixed in version 12.3.0 by adding mode validation in both the Python API and the C extension.
Affected products
- python-pillow Pillow < 12.3.0
Timeline
- 2026-07-07: disclosed: Reported to python-pillow/Pillow
- 2026-07-14: advisory: NVD published CVE-2026-59205
- 2026-07-20: patched: GitHub Advisory published and version 12.3.0 released