VDB
CVE-2026-59205
CVE-2026-59205
PUBLISHED
CVSS 7.5 HIGH
Reported by GitHub_M · Published July 14, 2026
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| python-pillow | Pillow | < 12.3.0 |
| python-pillow | Pillow | < 12.3.0 |
| chainguard | superset-6.0 | 0, 0, 0 |
| chainguard | text-generation-inference | 0, 0 |
| chainguard | openstack-horizon-2025.2-fips | 0, 0, 0 |
| wolfi | superset-6.1 | 0, 0, 0 |
| chainguard | openstack-horizon-2026.1-fips | 0, 0, 0 |
| chainguard | openstack-horizon-2025.2 | 0, 0, 0 |
| chainguard | lmcache-cuda-12.8 | 0 |
| chainguard | tritonserver-backend-vllm-cuda-13.0 | 0, 0 |
| chainguard | tensorflow-gpu-jupyter | 0, 0 |
| chainguard | openstack-horizon-2026.1 | 0, 0, 0 |
| chainguard | superset-fips-6.1 | 0 |
| wolfi | superset-6.0 | 0, 0, 0 |
| chainguard | superset-6.1 | 0, 0, 0 |
| chainguard | open-webui | 0, 0, 0 |
| chainguard | mlflow | 0, 0, 0 |
| chainguard | label-studio | 0, 0, 0 |
| wolfi | mlflow | 0, 0, 0 |
Timeline
- Jul 14, 2026 Coalition ESS Score
- Jul 14, 2026 CVE Published
- Jul 14, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 14, 2026 Security Advisory
References
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6 x_refsource_CONFIRM
- https://github.com/python-pillow/Pillow/pull/9715 x_refsource_MISC
- https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721 x_refsource_MISC
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0 x_refsource_MISC