Technology · PyPI
pillow (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 79 vulnerabilities in pillow (PyPI): 0 in the last 7 days and 16 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-59200, was published on 14 July 2026.
- Last 7 days
- 0
- Last 90 days
- 16
- Critical, all time
- 1
- Exploited in the wild
- 1
About pillow (PyPI)
A Python Imaging Library (PIL) fork that adds image processing capabilities to your Python interpreter.
Latest pillow (PyPI) vulnerabilities
- CVE-2026-59200: python-pillow Pillow denial of service in PdfParserhighCVSS 7.5EPSS 0.7%
- CVE-2026-59197: python-pillow Pillow heap out-of-bounds write in RankFilterhighCVSS 8.2EPSS 0.6%
- CVE-2026-54058: Pillow out-of-bounds read in McIdas AREA image parsinghighCVSS 4EPSS 0.7%
- CVE-2026-59205: Pillow heap corruption in ImageCmsTransform.applyhighCVSS 7.5EPSS 0.7%
- CVE-2026-59204: python-pillow Pillow denial of service in JPEG2000 decodinghighCVSS 4EPSS 0.7%
- CVE-2026-59203: Pillow infinite loop in EPS parser %%BeginBinary directivemediumCVSS 5.3EPSS 0.7%
- CVE-2026-59199: Pillow heap out-of-bounds write in image coordinate APIshighCVSS 7.5EPSS 0.7%
- CVE-2026-59198: Pillow TGA RLE encoder out-of-bounds readmediumCVSS 6.5EPSS 0.5%
- CVE-2024-28219: PYSEC-2026-1793 - Pillow buffer overflow vulnerabilitylowCVSS 3.1EPSS 1.0%
- CVE-2023-4863: PYSEC-2026-1794 - libwebp: OOB write in BuildHuffmanTablecriticalexploited in the wildCVSS 3.1EPSS 100.0%
- CVE-2026-55798: Python Pillow OS command injection in WindowsViewermediumCVSS 4.5EPSS 0.2%
- CVE-2026-55380: Pillow heap allocation overflow in GdImageFile decompression bomb checkhighCVSS 7.5EPSS 0.6%
- CVE-2026-55379: Pillow decompression bomb protection bypass in BdfFontFilehighCVSS 7.5EPSS 0.7%
- CVE-2026-54060: Python Pillow denial of service via excessive memory allocation in FontFilehighCVSS 7.5EPSS 0.6%
- CVE-2026-54059: Python Pillow memory exhaustion in PCF font parsinghighCVSS 7.5EPSS 0.6%
- CVE-2023-50447: PYSEC-2026-457 - Arbitrary Code Execution in PillowlowCVSS 3.1EPSS 1.7%
- CVE-2026-42311: Pillow integer overflow and OOB write in PSD processinghighCVSS 7.8EPSS 0.2%
- CVE-2026-42310: Pillow infinite loop in PDF trailer parsingmediumCVSS 5.5EPSS 0.2%
- CVE-2026-42309: Pillow heap buffer overflow in ImageDraw and ImagePath coordinatesmediumCVSS 5.5EPSS 0.2%
- CVE-2026-42308: Pillow integer overflow in font glyph processingmediumCVSS 5.5EPSS 0.2%
- CVE-2026-40192: Python Pillow denial of service via FITS GZIP decompression bombhighCVSS 7.5EPSS 0.9%
- CVE-2026-25990: python-pillow Pillow out-of-bounds write in PSD image loadinghighCVSS 7.5EPSS 0.4%
- CVE-2025-48379: PYSEC-2025-61 - Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow…lowCVSS 3.1EPSS 0.3%
- CVE-2023-44271: PYSEC-2023-227 - An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates…lowCVSS 3.1EPSS 1.1%
- PYSEC-2023-175 - Pillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to (previously ). Pillow v1info
Most severe pillow (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2023-4863: PYSEC-2026-1794 - libwebp: OOB write in BuildHuffmanTablecriticalexploited in the wildCVSS 3.1EPSS 100.0%
- CVE-2026-59197: python-pillow Pillow heap out-of-bounds write in RankFilterhighCVSS 8.2EPSS 0.6%
- CVE-2026-42311: Pillow integer overflow and OOB write in PSD processinghighCVSS 7.8EPSS 0.2%
- CVE-2026-40192: Python Pillow denial of service via FITS GZIP decompression bombhighCVSS 7.5EPSS 0.9%
- CVE-2026-59200: python-pillow Pillow denial of service in PdfParserhighCVSS 7.5EPSS 0.7%
- CVE-2026-59205: Pillow heap corruption in ImageCmsTransform.applyhighCVSS 7.5EPSS 0.7%
- CVE-2026-59199: Pillow heap out-of-bounds write in image coordinate APIshighCVSS 7.5EPSS 0.7%
- CVE-2026-55379: Pillow decompression bomb protection bypass in BdfFontFilehighCVSS 7.5EPSS 0.7%
- CVE-2026-55380: Pillow heap allocation overflow in GdImageFile decompression bomb checkhighCVSS 7.5EPSS 0.6%
- CVE-2026-54060: Python Pillow denial of service via excessive memory allocation in FontFilehighCVSS 7.5EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 7 | 1 | |
| 13 Jul 2026 | 8 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pillow.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "pillow (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pillow, 26 September 2026.