HIGH 7.5 PyPI
CVE-2026-59205
PYSEC-2026-3453 · BIT-pillow-2026-59205 · CVE-2026-59205 · GHSA-9hw9-ch79-4vh6
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.
References
- ADVISORY https://github.com/python-pillow/Pillow/releases/tag/12.3.0
- FIX https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721
- FIX https://github.com/python-pillow/Pillow/pull/9715
- EVIDENCE https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6
Ready to move
Start Securing
Free, no credit card | First findings in minutes