PT-2026-58089 · Pypi+2 · Pillow+2

CVE-2026-59198

·

Published

2026-06-23

·

Updated

2026-09-01

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Pillow versions 5.2.0 through 12.2.x
Description The TGA RLE encoder in the Pillow Python imaging library reads past its packed row buffer when saving a mode 1 image using TGA RLE compression. This behavior allows adjacent process heap bytes to be copied into the resulting TGA file.
Recommendations Update to version 12.3.0.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09899
BIT-PILLOW-2026-59198
CVE-2026-59198
ECHO-14CE-D866-AE2B
GHSA-FJ7V-R99M-22GQ
OESA-2026-3141
OESA-2026-3185
OESA-2026-3187
OESA-2026-3188
OESA-2026-3189
OPENSUSE-SU-2026:11283-1
OPENSUSE-SU-2026:21544-1
PYSEC-2026-3494
SUSE-SU-2026:23217-1
SUSE-SU-2026:23228-1
SUSE-SU-2026:3084-1
SUSE-SU-2026:3268-1
USN-8690-1

Affected Products

Linuxmint
Pillow
Ubuntu