PT-2026-58090 · Pypi · Pillow

CVE-2026-59199

·

Published

2026-07-14

·

Updated

2026-08-31

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Pillow versions prior to 12.3.0
Description Public image coordinate APIs in the Pillow Python imaging library can trigger a native heap out-of-bounds write. This occurs when coordinates near the signed 32-bit integer limits are provided to the Image.paste(), Image.crop(), or Image.alpha composite() functions.
Recommendations Update to version 12.3.0. As a temporary mitigation, avoid providing coordinates near the signed 32-bit integer limits to the Image.paste(), Image.crop(), and Image.alpha composite() functions.

Exploit

Fix

DoS

Memory Corruption

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PILLOW-2026-59199
CVE-2026-59199
ECHO-EED4-3DA2-904F
GHSA-6R8X-57C9-28J4
OESA-2026-3185
OESA-2026-3186
OESA-2026-3187
OESA-2026-3188
OESA-2026-3189
OPENSUSE-SU-2026:21544-1
PYSEC-2026-3451
SUSE-SU-2026:23217-1
SUSE-SU-2026:23228-1
SUSE-SU-2026:3084-1
SUSE-SU-2026:3268-1

Affected Products

Pillow