Known Vulnerabilities for Pillow by Python
Listed below are 10 of the newest known vulnerabilities associated with "Pillow" by "Python".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40192 json | Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when... | Not Provided | 2026-04-15 | 2026-04-16 |
| CVE-2023-50447 json | 8.1 - HIGH | 2024-01-19 | 2024-03-27 | |
| CVE-2023-44271 json | An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a ... | 7.5 - HIGH | 2023-11-03 | 2023-11-12 |
| CVE-2022-45199 json | Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL. | 7.5 - HIGH | 2022-11-14 | 2023-01-10 |
| CVE-2022-45198 json | Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification). | 7.5 - HIGH | 2022-11-14 | 2023-01-10 |
| CVE-2022-30595 json | libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files. | 9.8 - CRITICAL | 2022-05-25 | 2022-06-03 |
| CVE-2022-24303 json | Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled. | 9.1 - CRITICAL | 2022-03-28 | 2023-11-07 |
| CVE-2022-22817 json | PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec m... | 9.8 - CRITICAL | 2022-01-10 | 2023-12-10 |
| CVE-2022-22816 json | path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path. | 6.5 - MEDIUM | 2022-01-10 | 2023-01-31 |
| CVE-2022-22815 json | path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. | 6.5 - MEDIUM | 2022-01-10 | 2023-01-31 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Python | Pillow | 8.1.0 | |||
| Application | Python | Pillow | 8.0.1 | |||
| Application | Python | Pillow | 8.0.0 | |||
| Application | Python | Pillow | 7.2.0 | |||
| Application | Python | Pillow | 7.1.2 | |||
| Application | Python | Pillow | 7.1.1 | |||
| Application | Python | Pillow | 7.1.0 | |||
| Application | Python | Pillow | 7.0.0 | |||
| Application | Python | Pillow | 6.2.3 | |||
| Application | Python | Pillow | 6.2.2 | |||
| Application | Python | Pillow | 6.2.0 | |||
| Application | Python | Pillow | 6.0.0 | |||
| Application | Python | Pillow | 5.4.1 | |||
| Application | Python | Pillow | 5.4.0 | |||
| Application | Python | Pillow | 5.3.0 | |||
| Application | Python | Pillow | 5.2.0 | |||
| Application | Python | Pillow | 5.1.0 | |||
| Application | Python | Pillow | 5.0.0 | |||
| Application | Python | Pillow | 4.3.0 | |||
| Application | Python | Pillow | 4.2.1 |