{"schema_version":1,"title":"pillow (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 79 vulnerabilities in pillow (PyPI): 0 in the last 7 days and 15 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-59200, was published on 14 July 2026.","url":"https://junglewise.ai/threats/technologies/pillow","json_url":"https://junglewise.ai/threats/technologies/pillow.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pillow","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":13,"all_time":79,"critical":1,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":15,"last_365_days":21},"latest":[{"cve":"CVE-2026-59200","cvss":7.5,"epss":0.0066,"slug":"cve-2026-59200-python-pillow-pillow-denial-of-service-in-pdfparser","title":"python-pillow Pillow denial of service in PdfParser","severity":"high","exploited":false,"published_at":"2026-07-14T17:17:14.62+00:00","url":"https://junglewise.ai/threats/cve-2026-59200-python-pillow-pillow-denial-of-service-in-pdfparser"},{"cve":"CVE-2026-59197","cvss":8.2,"epss":0.0058,"slug":"cve-2026-59197-python-pillow-pillow-heap-out-of-bounds-write-in-rankfilter","title":"python-pillow Pillow heap out-of-bounds write in RankFilter","severity":"high","exploited":false,"published_at":"2026-07-14T17:17:14.487+00:00","url":"https://junglewise.ai/threats/cve-2026-59197-python-pillow-pillow-heap-out-of-bounds-write-in-rankfilter"},{"cve":"CVE-2026-54058","cvss":4,"epss":0.0068,"slug":"cve-2026-54058-pillow-out-of-bounds-read-in-mcidas-area-image-parsing","title":"Pillow out-of-bounds read in McIdas AREA image parsing","severity":"high","exploited":false,"published_at":"2026-07-14T17:17:03.433+00:00","url":"https://junglewise.ai/threats/cve-2026-54058-pillow-out-of-bounds-read-in-mcidas-area-image-parsing"},{"cve":"CVE-2026-59205","cvss":7.5,"epss":0.0066,"slug":"cve-2026-59205-pillow-heap-corruption-in-imagecmstransform-apply","title":"Pillow heap corruption in ImageCmsTransform.apply","severity":"high","exploited":false,"published_at":"2026-07-14T16:17:02.37+00:00","url":"https://junglewise.ai/threats/cve-2026-59205-pillow-heap-corruption-in-imagecmstransform-apply"},{"cve":"CVE-2026-59204","cvss":4,"epss":0.0066,"slug":"cve-2026-59204-python-pillow-pillow-denial-of-service-in-jpeg2000-decoding","title":"python-pillow Pillow denial of service in JPEG2000 decoding","severity":"high","exploited":false,"published_at":"2026-07-14T16:17:02.227+00:00","url":"https://junglewise.ai/threats/cve-2026-59204-python-pillow-pillow-denial-of-service-in-jpeg2000-decoding"},{"cve":"CVE-2026-59203","cvss":5.3,"epss":0.0066,"slug":"cve-2026-59203-pillow-infinite-loop-in-eps-parser-beginbinary-directive","title":"Pillow infinite loop in EPS parser %%BeginBinary directive","severity":"medium","exploited":false,"published_at":"2026-07-14T16:17:02.063+00:00","url":"https://junglewise.ai/threats/cve-2026-59203-pillow-infinite-loop-in-eps-parser-beginbinary-directive"},{"cve":"CVE-2026-59199","cvss":7.5,"epss":0.0066,"slug":"cve-2026-59199-pillow-heap-out-of-bounds-write-in-image-coordinate-apis","title":"Pillow heap out-of-bounds write in image coordinate APIs","severity":"high","exploited":false,"published_at":"2026-07-14T16:17:01.937+00:00","url":"https://junglewise.ai/threats/cve-2026-59199-pillow-heap-out-of-bounds-write-in-image-coordinate-apis"},{"cve":"CVE-2026-59198","cvss":6.5,"epss":0.005,"slug":"cve-2026-59198-pillow-tga-rle-encoder-out-of-bounds-read","title":"Pillow TGA RLE encoder out-of-bounds read","severity":"medium","exploited":false,"published_at":"2026-07-14T16:17:01.797+00:00","url":"https://junglewise.ai/threats/cve-2026-59198-pillow-tga-rle-encoder-out-of-bounds-read"},{"cve":"CVE-2024-28219","cvss":3.1,"epss":0.01,"slug":"cve-2024-28219-pillow-buffer-overflow-vulnerability","title":"PYSEC-2026-1793 - Pillow buffer overflow vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:37.25351+00:00","url":"https://junglewise.ai/threats/cve-2024-28219-pillow-buffer-overflow-vulnerability"},{"cve":"CVE-2026-55798","cvss":4.5,"epss":0.0018,"slug":"cve-2026-55798-python-pillow-os-command-injection-in-windowsviewer","title":"Python Pillow OS command injection in WindowsViewer","severity":"medium","exploited":false,"published_at":"2026-07-06T19:17:08.83+00:00","url":"https://junglewise.ai/threats/cve-2026-55798-python-pillow-os-command-injection-in-windowsviewer"},{"cve":"CVE-2026-55380","cvss":7.5,"epss":0.0064,"slug":"cve-2026-55380-pillow-heap-allocation-overflow-in-gdimagefile-decompression-bomb","title":"Pillow heap allocation overflow in GdImageFile decompression bomb check","severity":"high","exploited":false,"published_at":"2026-07-06T19:17:08.703+00:00","url":"https://junglewise.ai/threats/cve-2026-55380-pillow-heap-allocation-overflow-in-gdimagefile-decompression-bomb"},{"cve":"CVE-2026-55379","cvss":7.5,"epss":0.0065,"slug":"cve-2026-55379-pillow-decompression-bomb-protection-bypass-in-bdffontfile","title":"Pillow decompression bomb protection bypass in BdfFontFile","severity":"high","exploited":false,"published_at":"2026-07-06T19:17:08.577+00:00","url":"https://junglewise.ai/threats/cve-2026-55379-pillow-decompression-bomb-protection-bypass-in-bdffontfile"},{"cve":"CVE-2026-54060","cvss":7.5,"epss":0.0064,"slug":"cve-2026-54060-python-pillow-denial-of-service-via-excessive-memory-allocation","title":"Python Pillow denial of service via excessive memory allocation in FontFile","severity":"high","exploited":false,"published_at":"2026-07-06T19:17:08.27+00:00","url":"https://junglewise.ai/threats/cve-2026-54060-python-pillow-denial-of-service-via-excessive-memory-allocation"},{"cve":"CVE-2026-54059","cvss":7.5,"epss":0.0064,"slug":"cve-2026-54059-python-pillow-memory-exhaustion-in-pcf-font-parsing","title":"Python Pillow memory exhaustion in PCF font parsing","severity":"high","exploited":false,"published_at":"2026-07-06T19:17:08.127+00:00","url":"https://junglewise.ai/threats/cve-2026-54059-python-pillow-memory-exhaustion-in-pcf-font-parsing"},{"cve":"CVE-2023-50447","cvss":3.1,"epss":0.017,"slug":"cve-2023-50447-pillow-arbitrary-code-execution-in-imagemath-eval","title":"PYSEC-2026-457 - Arbitrary Code Execution in Pillow","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:41.331802+00:00","url":"https://junglewise.ai/threats/cve-2023-50447-pillow-arbitrary-code-execution-in-imagemath-eval"},{"cve":"CVE-2026-42311","cvss":7.8,"epss":0.0022,"slug":"cve-2026-42311-pillow-integer-overflow-and-oob-write-in-psd-processing","title":"Pillow integer overflow and OOB write in PSD processing","severity":"high","exploited":false,"published_at":"2026-05-09T06:16:10.43+00:00","url":"https://junglewise.ai/threats/cve-2026-42311-pillow-integer-overflow-and-oob-write-in-psd-processing"},{"cve":"CVE-2026-42310","cvss":5.5,"epss":0.0018,"slug":"cve-2026-42310-pillow-infinite-loop-in-pdf-trailer-parsing","title":"Pillow infinite loop in PDF trailer parsing","severity":"medium","exploited":false,"published_at":"2026-05-09T06:16:10.273+00:00","url":"https://junglewise.ai/threats/cve-2026-42310-pillow-infinite-loop-in-pdf-trailer-parsing"},{"cve":"CVE-2026-42309","cvss":5.5,"epss":0.0018,"slug":"cve-2026-42309-pillow-heap-buffer-overflow-in-imagedraw-and-imagepath","title":"Pillow heap buffer overflow in ImageDraw and ImagePath coordinates","severity":"medium","exploited":false,"published_at":"2026-05-09T06:16:10.073+00:00","url":"https://junglewise.ai/threats/cve-2026-42309-pillow-heap-buffer-overflow-in-imagedraw-and-imagepath"},{"cve":"CVE-2026-42308","cvss":5.5,"epss":0.0016,"slug":"cve-2026-42308-pillow-integer-overflow-in-font-glyph-processing","title":"Pillow integer overflow in font glyph processing","severity":"medium","exploited":false,"published_at":"2026-05-09T06:16:09.793+00:00","url":"https://junglewise.ai/threats/cve-2026-42308-pillow-integer-overflow-in-font-glyph-processing"},{"cve":"CVE-2026-40192","cvss":7.5,"epss":0.0087,"slug":"cve-2026-40192-python-pillow-denial-of-service-via-fits-gzip-decompression-bomb","title":"Python Pillow denial of service via FITS GZIP decompression bomb","severity":"high","exploited":false,"published_at":"2026-04-15T23:16:10.053+00:00","url":"https://junglewise.ai/threats/cve-2026-40192-python-pillow-denial-of-service-via-fits-gzip-decompression-bomb"},{"cve":"CVE-2026-25990","cvss":7.5,"epss":0.0044,"slug":"cve-2026-25990-python-pillow-pillow-out-of-bounds-write-in-psd-image-loading","title":"python-pillow Pillow out-of-bounds write in PSD image loading","severity":"high","exploited":false,"published_at":"2026-02-11T21:16:20.67+00:00","url":"https://junglewise.ai/threats/cve-2026-25990-python-pillow-pillow-out-of-bounds-write-in-psd-image-loading"},{"cve":"CVE-2025-48379","cvss":3.1,"epss":0.003,"slug":"cve-2025-48379-pillow-vulnerability-can-cause-write-buffer-overflow-on-bcn","title":"PYSEC-2025-61 - Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (","severity":"low","exploited":false,"published_at":"2025-07-01T19:15:27+00:00","url":"https://junglewise.ai/threats/cve-2025-48379-pillow-vulnerability-can-cause-write-buffer-overflow-on-bcn"},{"cve":"CVE-2023-44271","cvss":3.1,"epss":0.0113,"slug":"cve-2023-44271-pillow-denial-of-service-vulnerability","title":"PYSEC-2023-227 - An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, pot","severity":"low","exploited":false,"published_at":"2023-11-03T05:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-44271-pillow-denial-of-service-vulnerability"},{"slug":"pysec-2023-175-pillow-versions-before-v10-0-1-bundled-libwebp-binaries-9971d10a","title":"PYSEC-2023-175 - Pillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to (previously ). Pillow v1","severity":"info","exploited":false,"published_at":"2023-09-20T05:29:33+00:00","url":"https://junglewise.ai/threats/pysec-2023-175-pillow-versions-before-v10-0-1-bundled-libwebp-binaries-9971d10a"},{"cve":"CVE-2023-4863","cvss":3.1,"epss":0.9998,"slug":"cve-2023-4863-google-chromium-webp-heap-based-buffer-overflow-vulnerability","title":"RUSTSEC-2023-0060 - libwebp: OOB write in BuildHuffmanTable","severity":"critical","exploited":true,"published_at":"2023-09-12T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-4863-google-chromium-webp-heap-based-buffer-overflow-vulnerability"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"pillow (PyPI)","slug":"pillow","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://python-pillow.org/","repo_url":"https://github.com/python-pillow/Pillow","description":"A Python Imaging Library (PIL) fork that adds image processing capabilities to your Python interpreter.","url":"https://junglewise.ai/threats/technologies/pillow"},"most_severe":[{"cve":"CVE-2023-4863","cvss":3.1,"epss":0.9998,"slug":"cve-2023-4863-google-chromium-webp-heap-based-buffer-overflow-vulnerability","title":"RUSTSEC-2023-0060 - libwebp: OOB write in BuildHuffmanTable","severity":"critical","exploited":true,"published_at":"2023-09-12T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-4863-google-chromium-webp-heap-based-buffer-overflow-vulnerability"},{"cve":"CVE-2026-59197","cvss":8.2,"epss":0.0058,"slug":"cve-2026-59197-python-pillow-pillow-heap-out-of-bounds-write-in-rankfilter","title":"python-pillow Pillow heap out-of-bounds write in RankFilter","severity":"high","exploited":false,"published_at":"2026-07-14T17:17:14.487+00:00","url":"https://junglewise.ai/threats/cve-2026-59197-python-pillow-pillow-heap-out-of-bounds-write-in-rankfilter"},{"cve":"CVE-2026-42311","cvss":7.8,"epss":0.0022,"slug":"cve-2026-42311-pillow-integer-overflow-and-oob-write-in-psd-processing","title":"Pillow integer overflow and OOB write in PSD processing","severity":"high","exploited":false,"published_at":"2026-05-09T06:16:10.43+00:00","url":"https://junglewise.ai/threats/cve-2026-42311-pillow-integer-overflow-and-oob-write-in-psd-processing"},{"cve":"CVE-2026-40192","cvss":7.5,"epss":0.0087,"slug":"cve-2026-40192-python-pillow-denial-of-service-via-fits-gzip-decompression-bomb","title":"Python Pillow denial of service via FITS GZIP decompression bomb","severity":"high","exploited":false,"published_at":"2026-04-15T23:16:10.053+00:00","url":"https://junglewise.ai/threats/cve-2026-40192-python-pillow-denial-of-service-via-fits-gzip-decompression-bomb"},{"cve":"CVE-2026-59200","cvss":7.5,"epss":0.0066,"slug":"cve-2026-59200-python-pillow-pillow-denial-of-service-in-pdfparser","title":"python-pillow Pillow denial of service in PdfParser","severity":"high","exploited":false,"published_at":"2026-07-14T17:17:14.62+00:00","url":"https://junglewise.ai/threats/cve-2026-59200-python-pillow-pillow-denial-of-service-in-pdfparser"},{"cve":"CVE-2026-59205","cvss":7.5,"epss":0.0066,"slug":"cve-2026-59205-pillow-heap-corruption-in-imagecmstransform-apply","title":"Pillow heap corruption in ImageCmsTransform.apply","severity":"high","exploited":false,"published_at":"2026-07-14T16:17:02.37+00:00","url":"https://junglewise.ai/threats/cve-2026-59205-pillow-heap-corruption-in-imagecmstransform-apply"},{"cve":"CVE-2026-59199","cvss":7.5,"epss":0.0066,"slug":"cve-2026-59199-pillow-heap-out-of-bounds-write-in-image-coordinate-apis","title":"Pillow heap out-of-bounds write in image coordinate APIs","severity":"high","exploited":false,"published_at":"2026-07-14T16:17:01.937+00:00","url":"https://junglewise.ai/threats/cve-2026-59199-pillow-heap-out-of-bounds-write-in-image-coordinate-apis"},{"cve":"CVE-2026-55379","cvss":7.5,"epss":0.0065,"slug":"cve-2026-55379-pillow-decompression-bomb-protection-bypass-in-bdffontfile","title":"Pillow decompression bomb protection bypass in BdfFontFile","severity":"high","exploited":false,"published_at":"2026-07-06T19:17:08.577+00:00","url":"https://junglewise.ai/threats/cve-2026-55379-pillow-decompression-bomb-protection-bypass-in-bdffontfile"},{"cve":"CVE-2026-55380","cvss":7.5,"epss":0.0064,"slug":"cve-2026-55380-pillow-heap-allocation-overflow-in-gdimagefile-decompression-bomb","title":"Pillow heap allocation overflow in GdImageFile decompression bomb check","severity":"high","exploited":false,"published_at":"2026-07-06T19:17:08.703+00:00","url":"https://junglewise.ai/threats/cve-2026-55380-pillow-heap-allocation-overflow-in-gdimagefile-decompression-bomb"},{"cve":"CVE-2026-54060","cvss":7.5,"epss":0.0064,"slug":"cve-2026-54060-python-pillow-denial-of-service-via-excessive-memory-allocation","title":"Python Pillow denial of service via excessive memory allocation in FontFile","severity":"high","exploited":false,"published_at":"2026-07-06T19:17:08.27+00:00","url":"https://junglewise.ai/threats/cve-2026-54060-python-pillow-denial-of-service-via-excessive-memory-allocation"}],"generated_at":"2026-09-26T20:07:00.238639+00:00"}