VDB

CVE-2026-59205

CVE-2026-59205 PUBLISHED CVSS 7.5 HIGH

Reported by GitHub_M · Published July 14, 2026

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
python-pillowPillow< 12.3.0
python-pillowPillow< 12.3.0
chainguardsuperset-6.00, 0, 0
chainguardtext-generation-inference0, 0
chainguardopenstack-horizon-2025.2-fips0, 0, 0
wolfisuperset-6.10, 0, 0
chainguardopenstack-horizon-2026.1-fips0, 0, 0
chainguardopenstack-horizon-2025.20, 0, 0
chainguardlmcache-cuda-12.80
chainguardtritonserver-backend-vllm-cuda-13.00, 0
chainguardtensorflow-gpu-jupyter0, 0
chainguardopenstack-horizon-2026.10, 0, 0
chainguardsuperset-fips-6.10
wolfisuperset-6.00, 0, 0
chainguardsuperset-6.10, 0, 0
chainguardopen-webui0, 0, 0
chainguardmlflow0, 0, 0
chainguardlabel-studio0, 0, 0
wolfimlflow0, 0, 0

Timeline

  • Jul 14, 2026 Coalition ESS Score
  • Jul 14, 2026 CVE Published
  • Jul 14, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 14, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›