Security: python-pillow/Pillow
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of serviceGHSA-pg7v-jwj7-p798 published
Jul 7, 2026 by radarhereModerate -
WindowsViewer.get_command() OS command injection via unescaped shell path (CWE-78)GHSA-4x4j-2g7c-83w6 published
Jul 3, 2026 by radarhereModerate -
Heap buffer overflow with nested list coordinatesGHSA-5xmw-vc9v-4wf2 published
Apr 23, 2026 by aclark4lifeHigh -
Integer overflow when processing fontsGHSA-wjx4-4jcj-g98j published
Apr 23, 2026 by aclark4lifeHigh -
PDF Parsing Trailer Infinite Loop (DoS)GHSA-r73j-pqj5-w3x7 published
Apr 23, 2026 by aclark4lifeModerate -
OOB Write with Invalid PSD Tile Extents (Integer Overflow)GHSA-pwv6-vv43-88gr published
Apr 23, 2026 by aclark4lifeHigh -
FITS GZIP decompression bomb in Pillow < 12.2.0GHSA-whj4-6x5x-4v2j published
Apr 10, 2026 by aclark4lifeHigh -
Decompression Bomb DoS via PdfParser.PdfStream.decode()GHSA-jjj6-mw9f-p565 published
Jul 7, 2026 by radarhereHigh -
Out-of-bounds write when loading PSD imagesGHSA-cfh3-3jmp-rvhc published
Feb 11, 2026 by radarhereHigh -
Write buffer overflow on BCn encodingGHSA-xg8h-j46f-w952 published
Jul 1, 2025 by radarhereHigh