100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether pillow is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.5
PyPI

CVE-2026-55380

Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`

HIGH 7.5
PyPI

CVE-2026-59205

Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch

HIGH 7.5
PyPI

CVE-2026-54059

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

HIGH 7.5
PyPI

CVE-2026-59199

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

UNKNOWN
PyPI

CVE-2026-54058

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

HIGH 7.5
PyPI

CVE-2026-54060

Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

MEDIUM 4.5
PyPI

CVE-2026-55798

Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

MEDIUM 5.5
PyPI

CVE-2026-42309

Pillow has a heap buffer overflow with nested list coordinates

HIGH 7.5
PyPI

CVE-2026-40192

FITS GZIP decompression bomb in Pillow

UNKNOWN
PyPI

CVE-2026-25990

Pillow affected by out-of-bounds write when loading PSD images

MEDIUM 5.5
PyPI

CVE-2026-42310

Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

HIGH 8.2
PyPI

CVE-2026-59197

Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

UNKNOWN
PyPI

CVE-2026-59204

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

MEDIUM 5.3
PyPI

CVE-2026-59203

Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service

MEDIUM 6.5
PyPI

CVE-2026-59198

Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

HIGH 7.5
PyPI

CVE-2026-55379

Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

MEDIUM 5.5
PyPI

CVE-2026-42308

Pillow has an integer overflow when processing fonts

UNKNOWN
PyPI

CVE-2026-42311

Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)

HIGH 7.1
PyPI

CVE-2025-48379

Pillow vulnerability can cause write buffer overflow on BCn encoding

HIGH 7.5
PyPI

CVE-2026-59200

Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

MEDIUM 6.7
PyPI

CVE-2024-28219

Pillow buffer overflow vulnerability

HIGH 8.1
PyPI

CVE-2023-50447

Arbitrary Code Execution in Pillow

HIGH 8.8
crates.io KEV

CVE-2023-4863

libwebp: OOB write in BuildHuffmanTable

UNKNOWN
PyPI

CVE-2026-54058

Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

MEDIUM 6.5
PyPI

CVE-2026-59198

Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

HIGH 7.5
PyPI

CVE-2026-59200

Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

UNKNOWN
PyPI

CVE-2026-59204

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

HIGH 8.2
PyPI

CVE-2026-59197

CVE-2026-59197

HIGH 7.5
PyPI

CVE-2026-59199

CVE-2026-59199

HIGH 7.5
PyPI

CVE-2026-59203

CVE-2026-59203

HIGH 7.5
PyPI

CVE-2026-59205

CVE-2026-59205

MEDIUM 5.5
PyPI

CVE-2026-42310

Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

HIGH 7.5
PyPI

CVE-2026-54060

CVE-2026-54060

HIGH 7.8
PyPI

CVE-2026-42311

CVE-2026-42311

HIGH 7.5
PyPI

CVE-2026-25990

CVE-2026-25990

HIGH 7.5
PyPI

CVE-2026-54059

CVE-2026-54059

MEDIUM 4.5
PyPI

CVE-2026-55798

CVE-2026-55798

MEDIUM 5.5
PyPI

CVE-2026-42309

CVE-2026-42309

HIGH 7.5
PyPI

CVE-2026-55379

CVE-2026-55379

HIGH 7.5
PyPI

CVE-2026-40192

CVE-2026-40192

HIGH 7.5
PyPI

CVE-2026-55380

CVE-2026-55380

MEDIUM 6.7
PyPI

CVE-2024-28219

Pillow buffer overflow vulnerability

HIGH 8.8
PyPI KEV

CVE-2023-4863

libwebp: OOB write in BuildHuffmanTable

HIGH 8.1
PyPI

CVE-2023-50447

Arbitrary Code Execution in Pillow

UNKNOWN
PyPI

CVE-2014-1932

CVE-2014-1932

UNKNOWN
PyPI

CVE-2022-45198

CVE-2022-45198

UNKNOWN
PyPI

CVE-2022-45199

CVE-2022-45199

UNKNOWN
PyPI

CVE-2023-44271

CVE-2023-44271

UNKNOWN
PyPI

CVE-2014-3589

CVE-2014-3589

UNKNOWN
PyPI

CVE-2016-3076

CVE-2016-3076

UNKNOWN
PyPI

CVE-2014-9601

CVE-2014-9601

UNKNOWN
PyPI

CVE-2014-3598

CVE-2014-3598

UNKNOWN
PyPI

CVE-2014-3007

CVE-2014-3007

MEDIUM 5.5
PyPI

CVE-2026-42308

CVE-2026-42308

MEDIUM 6.5
PyPI

CVE-2016-2533

Pillow buffer overflow in ImagingPcdDecode

UNKNOWN
PyPI

CVE-2016-2533

CVE-2016-2533

UNKNOWN
PyPI

PYSEC-2023-175

PYSEC-2023-175

HIGH 7.5
PyPI

CVE-2021-27921

Pillow Denial of Service by Uncontrolled Resource Consumption

HIGH 7.5
PyPI

CVE-2021-27923

Pillow Denial of Service by Uncontrolled Resource Consumption

HIGH 7.5
PyPI

CVE-2021-27922

Pillow Uncontrolled Resource Consumption

UNKNOWN
PyPI

CVE-2025-48379

CVE-2025-48379

UNKNOWN
PyPI

CVE-2020-10379

CVE-2020-10379

HIGH 7.8
PyPI

CVE-2020-10379

Buffer overflow in Pillow

UNKNOWN
PyPI

CVE-2020-10378

CVE-2020-10378

MEDIUM 5.5
PyPI

CVE-2020-10378

Out-of-bounds read in Pillow

UNKNOWN
PyPI

GHSA-56pw-mpj4-fxww

Duplicate Advisory: Bundled libwebp in Pillow vulnerable

MEDIUM 4.0
PyPI

CVE-2014-1933

Pillow Temporary file name leakage

UNKNOWN
PyPI

GHSA-4fx9-vc88-q2xc

Infinite loop in Pillow

HIGH 7.5
PyPI

GHSA-jgpv-4h4c-xhw3

Uncontrolled Resource Consumption in pillow

HIGH 7.5
PyPI

CVE-2014-3598

Pillow is vulnerable to Denial of Service (DOS) in the Jpeg2KImagePlugin

HIGH 7.5
PyPI

CVE-2022-30595

Buffer over-flow in Pillow

CRITICAL 9.8
PyPI

CVE-2022-30595

CVE-2022-30595

HIGH 7.5
PyPI

CVE-2021-28677

Uncontrolled Resource Consumption in Pillow

MEDIUM 5.5
PyPI

CVE-2021-28678

Insufficient Verification of Data Authenticity in Pillow

HIGH 7.5
PyPI

CVE-2023-44271

Pillow Denial of Service vulnerability

HIGH 7.5
PyPI

CVE-2022-45199

Pillow subject to DoS via SAMPLESPERPIXEL tag

CRITICAL 9.1
PyPI

CVE-2022-24303

Path traversal in Pillow

HIGH 8.8
PyPI

CVE-2020-35654

Pillow Out-of-bounds Write

HIGH 7.5
PyPI

CVE-2022-45198

Pillow vulnerable to Data Amplification attack.

MEDIUM 6.5
PyPI

CVE-2022-22816

Out-of-bounds Read in Pillow

MEDIUM 6.5
PyPI

CVE-2022-22815

Improper Initialization in Pillow

CRITICAL 9.8
PyPI

CVE-2022-22817

Arbitrary expression injection in Pillow

HIGH 7.5
PyPI

CVE-2021-28676

Potential infinite loop in Pillow

MEDIUM 5.5
PyPI

CVE-2020-10177

Out-of-bounds reads in Pillow

CRITICAL 9.1
PyPI

CVE-2021-25288

Pillow Out-of-bounds Read vulnerability

HIGH 7.5
PyPI

CVE-2021-25291

Out of bounds read in Pillow

MEDIUM 5.5
PyPI

CVE-2016-3076

Pillow Buffer overflow in Jpeg2KEncode.c

CRITICAL 9.1
PyPI

CVE-2021-25287

Out-of-bounds Read in Pillow

MEDIUM 6.5
PyPI

CVE-2021-25292

Regular Expression Denial of Service (ReDoS) in Pillow

HIGH 7.5
PyPI

CVE-2019-16865

DOS attack in Pillow when processing specially crafted image files

CRITICAL 9.8
PyPI

CVE-2014-3007

Pillow command injection

CRITICAL 9.8
PyPI

CVE-2021-34552

Buffer Overflow in Pillow

HIGH 7.5
PyPI

CVE-2021-23437

Uncontrolled Resource Consumption in pillow

HIGH 7.5
PyPI

CVE-2014-9601

Pillow denial of service via PNG bomb

MEDIUM 6.5
PyPI

CVE-2016-0775

Pillow Buffer overflow in ImagingFliDecode

HIGH 7.5
PyPI

CVE-2021-25293

Out of bounds read in Pillow

HIGH 7.7
PyPI

CVE-2014-1932

PIL and Pillow Vulnerable to Symlink Attack on Tmpfiles

MEDIUM 5.5
PyPI

CVE-2021-28675

Pillow denial of service

HIGH 8.1
PyPI

CVE-2020-11538

Out-of-bounds read in Pillow

MEDIUM 5.5
PyPI

CVE-2020-10994

Out-of-bounds reads in Pillow

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes