Dependency scanning
Check whether pillow is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2023-4863
libwebp: OOB write in BuildHuffmanTable
CVE-2023-50447
Arbitrary Code Execution in Pillow
CVE-2023-50447
Arbitrary Code Execution in Pillow
CVE-2014-1932
CVE-2014-1932
CVE-2022-45198
CVE-2022-45198
CVE-2022-45199
CVE-2022-45199
CVE-2023-44271
CVE-2023-44271
CVE-2014-3589
CVE-2014-3589
CVE-2016-3076
CVE-2016-3076
CVE-2014-9601
CVE-2014-9601
CVE-2014-3598
CVE-2014-3598
CVE-2014-3007
CVE-2014-3007
CVE-2026-42308
Pillow has an integer overflow when processing fonts
CVE-2026-42308
CVE-2026-42308
CVE-2026-42310
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
CVE-2026-42311
Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
CVE-2026-42309
Pillow has a heap buffer overflow with nested list coordinates
CVE-2026-40192
FITS GZIP decompression bomb in Pillow
CVE-2026-25990
Pillow affected by out-of-bounds write when loading PSD images
CVE-2016-2533
Pillow buffer overflow in ImagingPcdDecode
CVE-2016-2533
CVE-2016-2533
CVE-2025-48379
Pillow vulnerability can cause write buffer overflow on BCn encoding
PYSEC-2023-175
PYSEC-2023-175
CVE-2024-28219
Pillow buffer overflow vulnerability
CVE-2021-27921
Pillow Denial of Service by Uncontrolled Resource Consumption
CVE-2021-27923
Pillow Denial of Service by Uncontrolled Resource Consumption
CVE-2021-27922
Pillow Uncontrolled Resource Consumption
CVE-2025-48379
CVE-2025-48379
CVE-2020-10379
CVE-2020-10379
CVE-2020-10379
Buffer overflow in Pillow
CVE-2020-10378
CVE-2020-10378
CVE-2020-10378
Out-of-bounds read in Pillow
GHSA-56pw-mpj4-fxww
Duplicate Advisory: Bundled libwebp in Pillow vulnerable
CVE-2014-1933
Pillow Temporary file name leakage
GHSA-4fx9-vc88-q2xc
Infinite loop in Pillow
GHSA-jgpv-4h4c-xhw3
Uncontrolled Resource Consumption in pillow
CVE-2014-3598
Pillow is vulnerable to Denial of Service (DOS) in the Jpeg2KImagePlugin
CVE-2022-30595
Buffer over-flow in Pillow
CVE-2022-30595
CVE-2022-30595
CVE-2021-28677
Uncontrolled Resource Consumption in Pillow
CVE-2021-28678
Insufficient Verification of Data Authenticity in Pillow
CVE-2023-44271
Pillow Denial of Service vulnerability
CVE-2022-45199
Pillow subject to DoS via SAMPLESPERPIXEL tag
CVE-2022-24303
Path traversal in Pillow
CVE-2020-35654
Pillow Out-of-bounds Write
CVE-2022-45198
Pillow vulnerable to Data Amplification attack.
CVE-2022-22816
Out-of-bounds Read in Pillow
CVE-2022-22815
Improper Initialization in Pillow
CVE-2022-22817
Arbitrary expression injection in Pillow
CVE-2021-28676
Potential infinite loop in Pillow
CVE-2020-10177
Out-of-bounds reads in Pillow
CVE-2021-25288
Pillow Out-of-bounds Read vulnerability
CVE-2021-25291
Out of bounds read in Pillow
CVE-2016-3076
Pillow Buffer overflow in Jpeg2KEncode.c
CVE-2021-25287
Out-of-bounds Read in Pillow
CVE-2021-25292
Regular Expression Denial of Service (ReDoS) in Pillow
CVE-2019-16865
DOS attack in Pillow when processing specially crafted image files
CVE-2014-3007
Pillow command injection
CVE-2021-34552
Buffer Overflow in Pillow
CVE-2021-23437
Uncontrolled Resource Consumption in pillow
CVE-2014-9601
Pillow denial of service via PNG bomb
CVE-2016-0775
Pillow Buffer overflow in ImagingFliDecode
CVE-2021-25293
Out of bounds read in Pillow
CVE-2014-1932
PIL and Pillow Vulnerable to Symlink Attack on Tmpfiles
CVE-2021-28675
Pillow denial of service
CVE-2020-11538
Out-of-bounds read in Pillow
CVE-2020-10994
Out-of-bounds reads in Pillow
CVE-2016-0740
Pillow Buffer overflow in ImagingLibTiffDecode
CVE-2020-5312
PCX P mode buffer overflow in Pillow
CVE-2021-25290
Out-of-bounds Write in Pillow
CVE-2014-3589
Pillow denial of service via Crafted Block Size
CVE-2020-35655
Pillow Out-of-bounds Read
CVE-2020-5311
Buffer Copy without Checking Size of Input in Pillow
CVE-2019-19911
Uncontrolled Resource Consumption in Pillow
CVE-2020-5310
Integer overflow in Pillow
CVE-2016-9189
Pillow Integer overflow in Map.c
CVE-2021-25289
Out of bounds write in Pillow
CVE-2020-35653
Pillow Out-of-bounds Read
CVE-2016-4009
Pillow Integer overflow in ImagingResampleHorizontal
CVE-2020-5313
Out-of-bounds Read in Pillow
CVE-2016-9190
Arbitrary code using "crafted image file" approach affecting Pillow
CVE-2022-24303
CVE-2022-24303
CVE-2022-22817
CVE-2022-22817
CVE-2022-22816
CVE-2022-22816
CVE-2022-22815
CVE-2022-22815
CVE-2021-34552
CVE-2021-34552
CVE-2021-28678
CVE-2021-28678
CVE-2021-28677
CVE-2021-28677
CVE-2021-28676
CVE-2021-28676
CVE-2021-28675
CVE-2021-28675
CVE-2021-27923
CVE-2021-27923
CVE-2021-27922
CVE-2021-27922
CVE-2021-27921
CVE-2021-27921
CVE-2021-25293
CVE-2021-25293
CVE-2021-25292
CVE-2021-25292
CVE-2021-25291
CVE-2021-25291
CVE-2021-25290
CVE-2021-25290
CVE-2021-25289
CVE-2021-25289
CVE-2021-25288
CVE-2021-25288
CVE-2021-25287
CVE-2021-25287
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes