Security: python-pillow/Pillow
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatchGHSA-9hw9-ch79-4vh6 published
Jul 7, 2026 by radarhereHigh -
Heap out-of-bounds write in Pillow `Image.paste()` / `Image.crop()` via signed coordinate overflowGHSA-6r8x-57c9-28j4 published
Jul 7, 2026 by radarhereHigh -
`FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`GHSA-5x94-69rx-g8h2 published
Jul 3, 2026 by radarhereHigh -
PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loadingGHSA-8v84-f9pq-wr9x published
Jul 3, 2026 by radarhereHigh -
BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loadingGHSA-45hq-cxwh-f6vc published
Jul 3, 2026 by radarhereHigh -
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated imagesGHSA-fj7v-r99m-22gq published
Jul 7, 2026 by radarhereModerate -
Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`GHSA-xj96-63gp-2gmr published
Jul 7, 2026 by radarhereHigh -
Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)GHSA-62p4-gmf7-7g93 published
Jul 7, 2026 by radarhereHigh -
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of serviceGHSA-vjc4-5qp5-m44j published
Jul 7, 2026 by radarhereModerate