Skip to content
RequestGuard Vulnerabilities
Pricing

pillow

Python Imaging Library (fork)

PyPI latest 12.3.0 MIT-CMU

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

12.3.0

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

79 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

79

PCX P mode buffer overflow in Pillow

Affected range

ECOSYSTEM: introduced 0; fixed 6.2.2GIT: introduced 0; fixed 93b22b846e0269ee9594ff71a72bec02d2bea8fd

Fixed versions: 6.2.2, 93b22b846e0269ee9594ff71a72bec02d2bea8fd

Buffer Copy without Checking Size of Input in Pillow

Affected range

ECOSYSTEM: introduced 0; fixed 6.2.2GIT: introduced 0; fixed a79b65c47c7dc6fe623aadf09aa6192fc54548f3

Fixed versions: 6.2.2, a79b65c47c7dc6fe623aadf09aa6192fc54548f3

Integer overflow in Pillow

Affected range

ECOSYSTEM: introduced 0; fixed 6.2.2GIT: introduced 0; fixed 4e2def2539ec13e53a82e06c4b3daf00454100c4

Fixed versions: 6.2.2, 4e2def2539ec13e53a82e06c4b3daf00454100c4

Pillow Integer overflow in ImagingResampleHorizontal

Affected range

ECOSYSTEM: introduced 0; fixed 3.1.1GIT: introduced 0; fixed 4e0d9b0b9740d258ade40cce248c93777362ac1e

Fixed versions: 3.1.1, 4e0d9b0b9740d258ade40cce248c93777362ac1e

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

Affected range

ECOSYSTEM: introduced 0; fixed 12.3.0

Fixed versions: 12.3.0

Show 54 more advisories
GHSA-pg7v-jwj7-p798 Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
GHSA-45hq-cxwh-f6vc Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
GHSA-pwv6-vv43-88gr Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
GHSA-xg8h-j46f-w952 Pillow vulnerability can cause write buffer overflow on BCn encoding
GHSA-jjj6-mw9f-p565 Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
GHSA-44wm-f244-xhp3 Pillow buffer overflow vulnerability
GHSA-3c5c-7235-994j Pillow buffer overflow in ImagingPcdDecode
GHSA-f4w8-cv6p-x6r5 Pillow Denial of Service by Uncontrolled Resource Consumption
GHSA-95q3-8gr9-gm8w Pillow Denial of Service by Uncontrolled Resource Consumption
GHSA-3wvg-mj6g-m9cv Pillow Uncontrolled Resource Consumption
GHSA-8843-m7mw-mxqm Buffer overflow in Pillow
GHSA-3xv8-3j54-hgrp Out-of-bounds read in Pillow
GHSA-jgpv-4h4c-xhw3 Uncontrolled Resource Consumption in pillow
GHSA-j6f7-g425-4gmx Pillow is vulnerable to Denial of Service (DOS) in the Jpeg2KImagePlugin
GHSA-q5hq-fp76-qmrc Uncontrolled Resource Consumption in Pillow
GHSA-8ghj-p4vj-mr35 Pillow Denial of Service vulnerability
GHSA-q4mp-jvh2-76fj Pillow subject to DoS via SAMPLESPERPIXEL tag
GHSA-vqcj-wrf2-7v73 Pillow Out-of-bounds Write
GHSA-m2vv-5vj5-2hm7 Pillow vulnerable to Data Amplification attack.
GHSA-7r7m-5h27-29hp Potential infinite loop in Pillow
GHSA-cqhg-xjhh-p8hf Out-of-bounds reads in Pillow
GHSA-mvg9-xffr-p774 Out of bounds read in Pillow
GHSA-v9pc-9mvp-x87g Pillow Buffer overflow in Jpeg2KEncode.c
GHSA-j7mj-748x-7p78 DOS attack in Pillow when processing specially crafted image files
GHSA-98vv-pw6r-q6q4 Uncontrolled Resource Consumption in pillow
GHSA-h5rf-vgqx-wjv2 Pillow denial of service via PNG bomb
GHSA-8xjv-v9xq-m5h9 Pillow Buffer overflow in ImagingFliDecode
GHSA-p43w-g3c5-g5mq Out of bounds read in Pillow
GHSA-x895-2wrm-hvp7 PIL and Pillow Vulnerable to Symlink Attack on Tmpfiles
GHSA-g6rj-rv7j-xwp4 Pillow denial of service
GHSA-vj42-xq3r-hr3r Out-of-bounds reads in Pillow
GHSA-8xjq-8fcg-g5hw Out-of-bounds Write in Pillow
GHSA-cfmr-38g9-f2h7 Pillow denial of service via Crafted Block Size
GHSA-5gm3-px64-rw72 Uncontrolled Resource Consumption in Pillow
GHSA-f5g8-5qq7-938w Pillow Out-of-bounds Read
GHSA-hj69-c76v-86wr Out-of-bounds Read in Pillow
GHSA-w4vg-rf63-f3j3 Arbitrary code using "crafted image file" approach affecting Pillow
GHSA-4x4j-2g7c-83w6 Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
GHSA-5xmw-vc9v-4wf2 Pillow has a heap buffer overflow with nested list coordinates
GHSA-r73j-pqj5-w3x7 Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
GHSA-fj7v-r99m-22gq Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
GHSA-wjx4-4jcj-g98j Pillow has an integer overflow when processing fonts
GHSA-r854-96gq-rfg3 Pillow Temporary file name leakage
GHSA-hjfx-8p6c-g7gx Insufficient Verification of Data Authenticity in Pillow
GHSA-xrcv-f9gm-v42c Out-of-bounds Read in Pillow
GHSA-pw3c-h7wp-cvhx Improper Initialization in Pillow
GHSA-9hx2-hgq2-2g4f Regular Expression Denial of Service (ReDoS) in Pillow
GHSA-hggx-3h72-49ww Pillow Buffer overflow in ImagingLibTiffDecode
GHSA-hf64-x4gq-p99h Pillow Out-of-bounds Read
GHSA-rwr3-c2q8-gm56 Pillow Integer overflow in Map.c
GHSA-4fx9-vc88-q2xc Infinite loop in Pillow
PYSEC-2023-175 Pillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). Pillow v10.0.1 upgrades the bundled libwebp binary to v1.3.2.
OSV-2022-1074 Invalid-free in _dealloc
OSV-2022-715 Segv on unknown address in jpeg_read_scanlines