© 2025-2026 PySpect
No release of pillow is currently known to be free of vulnerabilities.
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
Fixed in: 12.3.0
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
Fixed in: 12.3.0
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
Fixed in: 12.3.0
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
Fixed in: 12.3.0
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
Fixed in: 12.3.0
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Fixed in: 12.3.0
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
Fixed in: 12.3.0
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
Fixed in: 12.3.0
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
Fixed in: 12.3.0
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
Fixed in: 12.3.0
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
Fixed in: 12.3.0
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
Fixed in: 12.3.0
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
Fixed in: 12.3.0
Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
Fixed in: 12.2.0
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
Fixed in: 12.2.0
Pillow has an integer overflow when processing fonts
Fixed in: 12.2.0
Pillow has a heap buffer overflow with nested list coordinates
Fixed in: 12.2.0
FITS GZIP decompression bomb in Pillow
Fixed in: 12.2.0
Pillow affected by out-of-bounds write when loading PSD images
Fixed in: 12.1.1
Pillow vulnerability can cause write buffer overflow on BCn encoding
Fixed in: 11.3.0, 89f1f4626a2aaf5f3d5ca6437f41def2998fbe09, ef98b3510e3e4f14b547762764813d7e5ca3c5a4
Pillow buffer overflow vulnerability
Fixed in: 10.3.0
Arbitrary Code Execution in Pillow
Fixed in: 10.2.0
Pillow Denial of Service vulnerability
Fixed in: 10.0.0, 1fe1bb49c452b0318cad12ea9d97c3bef188e9a7
Pillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). Pillow v10.0.1 upgrades the bundled libwebp binary to v1.3.2.
Fixed in: 10.0.1
libwebp: OOB write in BuildHuffmanTable
Fixed in: 0.1.8, 0.9.3, 22.3.24, 24.8.3, 25.8.1, 26.2.1, 27.0.0-beta.2, 2.88.6, 1.4.0, 10.0.1, 0.2.6, 13.3.0, 0.0.0-20250406010349-76805d5a8860, 1.1.2-0.20250406010349-76805d5a8860
Pillow vulnerable to Data Amplification attack.
Fixed in: 9.2.0, 11918eac0628ec8ac0812670d9838361ead2d6a4
Pillow subject to DoS via SAMPLESPERPIXEL tag
Fixed in: 9.3.0, 2444cddab2f83f28687c7c20871574acbb6dbcf3
Invalid-free in _dealloc
Fixed in: f7363c1091c70356d92e56abfca6b65bef9e7b26
Segv on unknown address in jpeg_read_scanlines
Fixed in: 9887544fafcd13cc8afcfa0c6d0f2e6facc1a8b8
Buffer over-flow in Pillow
Fixed in: 9.1.1
Buffer Copy without Checking Size of Input in Pillow
Fixed in: 6.2.2, a79b65c47c7dc6fe623aadf09aa6192fc54548f3
Pillow command injection
Fixed in: 2.5.0
Pillow Buffer overflow in Jpeg2KEncode.c
Fixed in: 3.1.2
PIL and Pillow Vulnerable to Symlink Attack on Tmpfiles
Fixed in: 2.3.1, 4e9f367dfd3f04c8f5d23f7f759ec12782e10ee7
Pillow denial of service via PNG bomb
Fixed in: 2.7.0
Pillow denial of service via Crafted Block Size
Fixed in: 2.3.2, 2.5.2, 205e056f8f9b06ed7b925cf8aa0874bc4aaf8a7d
Pillow is vulnerable to Denial of Service (DOS) in the Jpeg2KImagePlugin
Fixed in: 2.5.3
Infinite loop in Pillow
Fixed in: 9.0.0
Path traversal in Pillow
Fixed in: 9.0.1
Improper Initialization in Pillow
Fixed in: 9.0.0
Out-of-bounds Read in Pillow
Fixed in: 9.0.0
Arbitrary expression injection in Pillow
Fixed in: 9.0.1, 9.0.0
PCX P mode buffer overflow in Pillow
Fixed in: 6.2.2, 93b22b846e0269ee9594ff71a72bec02d2bea8fd
Out-of-bounds read in Pillow
Fixed in: 7.1.0, 6a83e4324738bb0452fbe8074a995b1c73f08de7
Integer overflow in Pillow
Fixed in: 6.2.2, 4e2def2539ec13e53a82e06c4b3daf00454100c4
Buffer Overflow in Pillow
Fixed in: 8.3.0
Uncontrolled Resource Consumption in pillow
Fixed in: 8.3.2, 9e08eb8f78fdfd2f476e1b20b7cf38683754866b
Uncontrolled Resource Consumption in Pillow
Fixed in: 8.2.0
Pillow Out-of-bounds Read vulnerability
Fixed in: 8.2.0
Insufficient Verification of Data Authenticity in Pillow
Fixed in: 8.2.0
Pillow denial of service
Fixed in: 8.2.0
Out-of-bounds Read in Pillow
Fixed in: 8.2.0
Potential infinite loop in Pillow
Fixed in: 8.2.0
Uncontrolled Resource Consumption in pillow
Fixed in: 8.1.2
Out of bounds read in Pillow
Fixed in: 8.2.0, 8.1.1
Regular Expression Denial of Service (ReDoS) in Pillow
Fixed in: 8.1.1
Out-of-bounds Write in Pillow
Fixed in: 8.1.1
Out of bounds read in Pillow
Fixed in: 8.1.1
Out of bounds write in Pillow
Fixed in: 8.1.1
Pillow Out-of-bounds Read
Fixed in: 8.1.0
Pillow Out-of-bounds Read
Fixed in: 8.1.0
Pillow Out-of-bounds Write
Fixed in: 8.1.0
Pillow Uncontrolled Resource Consumption
Fixed in: 8.1.2, 8.1.1
Pillow Denial of Service by Uncontrolled Resource Consumption
Fixed in: 8.1.2, 8.1.1
Pillow Denial of Service by Uncontrolled Resource Consumption
Fixed in: 8.1.2, 8.1.1
Out-of-bounds reads in Pillow
Fixed in: 7.1.0
Buffer overflow in Pillow
Fixed in: 7.1.0, 46f4a349b88915787fea3fb91348bb1665831bbb
Out-of-bounds reads in Pillow
Fixed in: 7.1.0, 7.0.0
Out-of-bounds read in Pillow
Fixed in: 7.1.0
Pillow Temporary file name leakage
Fixed in: 2.3.1, 4e9f367dfd3f04c8f5d23f7f759ec12782e10ee7
Uncontrolled Resource Consumption in Pillow
Fixed in: 6.2.2
Out-of-bounds Read in Pillow
Fixed in: 6.2.2, a09acd0decd8a87ccce939d5ff65dab59e7d365b
DOS attack in Pillow when processing specially crafted image files
Fixed in: 6.2.0
Pillow Integer overflow in ImagingResampleHorizontal
Fixed in: 3.1.1, 4e0d9b0b9740d258ade40cce248c93777362ac1e
Pillow Buffer overflow in ImagingFliDecode
Fixed in: 3.1.1, 893a40850c2d5da41537958e40569c029a6e127b
Pillow buffer overflow in ImagingPcdDecode
Fixed in: 3.1.1, 5bdf54b5a76b54fb00bd05f2d733e0a4173eefc9, ae453aa18b66af54e7ff716f4ccb33adca60afd4
Pillow Integer overflow in Map.c
Fixed in: 3.3.2
Pillow Buffer overflow in ImagingLibTiffDecode
Fixed in: 3.1.1, 6dcbf5bd96b717c58d7b642949da8d323099928e
Arbitrary code using "crafted image file" approach affecting Pillow
Fixed in: 3.3.2