VendorsPythonpillowany version
Vulnerabilities

Python Pillow any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

69CVEs
CVE-2016-4009
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.
Published 2016-04-13 · Modified
10.0EPSS 0.079
CVE-2020-5311
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
Published 2020-01-03 · Modified
9.8EPSS 0.042
CVE-2020-5312
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
Published 2020-01-03 · Modified
9.8EPSS 0.037
CVE-2022-22817
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used.
Published 2022-01-07 · Modified
9.8EPSS 0.033
CVE-2021-34552
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
Published 2021-07-13 · Modified
9.8EPSS 0.032
CVE-2021-25289
An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOTE: this issue exists because of an incomplete fix for CVE-2020-35654.
Published 2021-03-19 · Modified
9.8EPSS 0.023
CVE-2021-25287
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.
Published 2021-06-02 · Modified
9.1EPSS 0.029
CVE-2022-24303
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Published 2022-03-28 · Modified
9.1EPSS 0.027
CVE-2021-25288
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.
Published 2021-06-02 · Modified
9.1EPSS 0.024
CVE-2026-54058
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
Published 2026-07-14 · Analyzed
9.1EPSS 0.005
CVE-2020-5310
libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
Published 2020-01-03 · Modified
8.8EPSS 0.020
CVE-2020-35654
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
Published 2021-01-12 · Modified
8.8EPSS 0.018
CVE-2026-40192
Pillow is vulnerable to a FITS GZIP decompression bomb
Published 2026-04-15 · Modified
8.7EPSS 0.007
CVE-2026-59204
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
Published 2026-07-14 · Modified
8.7EPSS 0.004
CVE-2026-25990
Pillow has an out-of-bounds write when loading PSD images
Published 2026-02-11 · Modified
8.6EPSS 0.004
CVE-2026-42311
Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)
Published 2026-05-09 · Analyzed
8.6EPSS 0.002
CVE-2026-59197
Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
Published 2026-07-14 · Modified
8.2EPSS 0.004
CVE-2020-11538
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
Published 2020-06-25 · Modified
8.1EPSS 0.025
CVE-2023-50447
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
Published 2024-01-19 · Modified
8.1EPSS 0.017
CVE-2016-9190
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.
Published 2016-11-04 · Modified
7.8EPSS 0.019
CVE-2020-10379
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
Published 2020-06-25 · Modified
7.8EPSS 0.011
CVE-2021-27922
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
Published 2021-03-03 · Modified
7.5EPSS 0.049
CVE-2021-23437
Regular Expression Denial of Service (ReDoS)
Published 2021-09-03 · Modified
7.5EPSS 0.032
CVE-2021-27921
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
Published 2021-03-03 · Modified
7.5EPSS 0.032
CVE-2019-16865
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
Published 2019-10-04 · Modified
7.5EPSS 0.031
CVE-2021-27923
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.
Published 2021-03-03 · Modified
7.5EPSS 0.030
CVE-2021-28676
An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.
Published 2021-06-02 · Modified
7.5EPSS 0.025
CVE-2021-25290
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
Published 2021-03-19 · Modified
7.5EPSS 0.024
CVE-2021-28677
An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.
Published 2021-06-02 · Modified
7.5EPSS 0.023
CVE-2019-19911
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.
Published 2020-01-05 · Modified
7.5EPSS 0.021
CVE-2021-25293
An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.
Published 2021-03-19 · Modified
7.5EPSS 0.016
CVE-2021-25291
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.
Published 2021-03-19 · Modified
7.5EPSS 0.014
CVE-2022-45198
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
Published 2022-11-14 · Modified
7.5EPSS 0.013
CVE-2022-45199
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
Published 2022-11-14 · Modified
7.5EPSS 0.012
CVE-2023-44271
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
Published 2023-11-03 · Modified
7.5EPSS 0.011
CVE-2026-59203
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
Published 2026-07-14 · Modified
7.5EPSS 0.007
CVE-2026-55379
Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
Published 2026-07-06 · Analyzed
7.5EPSS 0.004
CVE-2026-55380
Pillow GdImageFile decompression bomb protection bypass
Published 2026-07-06 · Analyzed
7.5EPSS 0.004
CVE-2026-54060
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
Published 2026-07-06 · Analyzed
7.5EPSS 0.004
CVE-2026-54059
Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
Published 2026-07-06 · Analyzed
7.5EPSS 0.004
1 / 2Next →