Dependency scanning
Check whether pillow is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-55380
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
CVE-2026-59205
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
CVE-2026-54059
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
CVE-2026-59199
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
CVE-2026-54058
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
CVE-2026-54060
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
CVE-2026-55798
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
CVE-2026-42309
Pillow has a heap buffer overflow with nested list coordinates
CVE-2026-40192
FITS GZIP decompression bomb in Pillow
CVE-2026-25990
Pillow affected by out-of-bounds write when loading PSD images
CVE-2026-42310
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
CVE-2026-59197
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
CVE-2026-59204
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
CVE-2026-59203
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
CVE-2026-59198
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
CVE-2026-55379
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
CVE-2026-42308
Pillow has an integer overflow when processing fonts
CVE-2026-42311
Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
CVE-2025-48379
Pillow vulnerability can cause write buffer overflow on BCn encoding
CVE-2026-59200
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
CVE-2024-28219
Pillow buffer overflow vulnerability
CVE-2023-50447
Arbitrary Code Execution in Pillow
CVE-2023-4863
libwebp: OOB write in BuildHuffmanTable
CVE-2026-54058
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
CVE-2026-59198
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
CVE-2026-59200
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
CVE-2026-59204
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
CVE-2026-59197
CVE-2026-59197
CVE-2026-59199
CVE-2026-59199
CVE-2026-59203
CVE-2026-59203
CVE-2026-59205
CVE-2026-59205
CVE-2026-42310
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
CVE-2026-54060
CVE-2026-54060
CVE-2026-42311
CVE-2026-42311
CVE-2026-25990
CVE-2026-25990
CVE-2026-54059
CVE-2026-54059
CVE-2026-55798
CVE-2026-55798
CVE-2026-42309
CVE-2026-42309
CVE-2026-55379
CVE-2026-55379
CVE-2026-40192
CVE-2026-40192
CVE-2026-55380
CVE-2026-55380
CVE-2024-28219
Pillow buffer overflow vulnerability
CVE-2023-4863
libwebp: OOB write in BuildHuffmanTable
CVE-2023-50447
Arbitrary Code Execution in Pillow
CVE-2014-1932
CVE-2014-1932
CVE-2022-45198
CVE-2022-45198
CVE-2022-45199
CVE-2022-45199
CVE-2023-44271
CVE-2023-44271
CVE-2014-3589
CVE-2014-3589
CVE-2016-3076
CVE-2016-3076
CVE-2014-9601
CVE-2014-9601
CVE-2014-3598
CVE-2014-3598
CVE-2014-3007
CVE-2014-3007
CVE-2026-42308
CVE-2026-42308
CVE-2016-2533
Pillow buffer overflow in ImagingPcdDecode
CVE-2016-2533
CVE-2016-2533
PYSEC-2023-175
PYSEC-2023-175
CVE-2021-27921
Pillow Denial of Service by Uncontrolled Resource Consumption
CVE-2021-27923
Pillow Denial of Service by Uncontrolled Resource Consumption
CVE-2021-27922
Pillow Uncontrolled Resource Consumption
CVE-2025-48379
CVE-2025-48379
CVE-2020-10379
CVE-2020-10379
CVE-2020-10379
Buffer overflow in Pillow
CVE-2020-10378
CVE-2020-10378
CVE-2020-10378
Out-of-bounds read in Pillow
GHSA-56pw-mpj4-fxww
Duplicate Advisory: Bundled libwebp in Pillow vulnerable
CVE-2014-1933
Pillow Temporary file name leakage
GHSA-4fx9-vc88-q2xc
Infinite loop in Pillow
GHSA-jgpv-4h4c-xhw3
Uncontrolled Resource Consumption in pillow
CVE-2014-3598
Pillow is vulnerable to Denial of Service (DOS) in the Jpeg2KImagePlugin
CVE-2022-30595
Buffer over-flow in Pillow
CVE-2022-30595
CVE-2022-30595
CVE-2021-28677
Uncontrolled Resource Consumption in Pillow
CVE-2021-28678
Insufficient Verification of Data Authenticity in Pillow
CVE-2023-44271
Pillow Denial of Service vulnerability
CVE-2022-45199
Pillow subject to DoS via SAMPLESPERPIXEL tag
CVE-2022-24303
Path traversal in Pillow
CVE-2020-35654
Pillow Out-of-bounds Write
CVE-2022-45198
Pillow vulnerable to Data Amplification attack.
CVE-2022-22816
Out-of-bounds Read in Pillow
CVE-2022-22815
Improper Initialization in Pillow
CVE-2022-22817
Arbitrary expression injection in Pillow
CVE-2021-28676
Potential infinite loop in Pillow
CVE-2020-10177
Out-of-bounds reads in Pillow
CVE-2021-25288
Pillow Out-of-bounds Read vulnerability
CVE-2021-25291
Out of bounds read in Pillow
CVE-2016-3076
Pillow Buffer overflow in Jpeg2KEncode.c
CVE-2021-25287
Out-of-bounds Read in Pillow
CVE-2021-25292
Regular Expression Denial of Service (ReDoS) in Pillow
CVE-2019-16865
DOS attack in Pillow when processing specially crafted image files
CVE-2014-3007
Pillow command injection
CVE-2021-34552
Buffer Overflow in Pillow
CVE-2021-23437
Uncontrolled Resource Consumption in pillow
CVE-2014-9601
Pillow denial of service via PNG bomb
CVE-2016-0775
Pillow Buffer overflow in ImagingFliDecode
CVE-2021-25293
Out of bounds read in Pillow
CVE-2014-1932
PIL and Pillow Vulnerable to Symlink Attack on Tmpfiles
CVE-2021-28675
Pillow denial of service
CVE-2020-11538
Out-of-bounds read in Pillow
CVE-2020-10994
Out-of-bounds reads in Pillow
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes