VDB

CVE-2026-59205

CVE-2026-59205 PUBLISHED CVSS 7.5 HIGH

Reported by GitHub_M · Published July 14, 2026

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
python-pillowPillow< 12.3.0
python-pillowPillow< 12.3.0, < 12.3.0
chainguardsuperset-6.00, 0, 0
chainguardtext-generation-inference0, 0, 0
chainguardopenstack-horizon-2025.2-fips0, 0, 0
wolfisuperset-6.10, 0, 0
chainguardopenstack-horizon-2026.1-fips0, 0, 0
chainguardopenstack-horizon-2025.20, 0, 0
chainguardlmcache-cuda-12.80, 0, 0
wolfiopen-webui0, 0, 0
chainguardtritonserver-backend-vllm-cuda-13.00, 0, 0
PyPIPillow0
chainguardtensorflow-gpu-jupyter0, 0, 0
chainguardopenstack-horizon-2026.10, 0, 0
chainguardsuperset-fips-6.10, 0, 0
wolfisuperset-6.00, 0, 0
chainguardsuperset-6.10, 0, 0
chainguardopen-webui0, 0, 0
python-pillowPillow
chainguardmlflow0, 0, 0

…and 2 more

Timeline

  • Jul 14, 2026 Coalition ESS Score
  • Jul 14, 2026 CVE Published
  • Aug 7, 2026 EPSS Score
  • Aug 14, 2026 Security Advisory
  • Aug 27, 2026 EPSS Score
  • Sep 1, 2026 EPSS Score
  • Sep 4, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›