VDB
CVE-2026-59205
CVE-2026-59205
PUBLISHED
CVSS 7.5 HIGH
Reported by GitHub_M · Published July 14, 2026
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| python-pillow | Pillow | < 12.3.0 |
| python-pillow | Pillow | < 12.3.0, < 12.3.0 |
| chainguard | superset-6.0 | 0, 0, 0 |
| chainguard | text-generation-inference | 0, 0, 0 |
| chainguard | openstack-horizon-2025.2-fips | 0, 0, 0 |
| wolfi | superset-6.1 | 0, 0, 0 |
| chainguard | openstack-horizon-2026.1-fips | 0, 0, 0 |
| chainguard | openstack-horizon-2025.2 | 0, 0, 0 |
| chainguard | lmcache-cuda-12.8 | 0, 0, 0 |
| wolfi | open-webui | 0, 0, 0 |
| chainguard | tritonserver-backend-vllm-cuda-13.0 | 0, 0, 0 |
| PyPI | Pillow | 0 |
| chainguard | tensorflow-gpu-jupyter | 0, 0, 0 |
| chainguard | openstack-horizon-2026.1 | 0, 0, 0 |
| chainguard | superset-fips-6.1 | 0, 0, 0 |
| wolfi | superset-6.0 | 0, 0, 0 |
| chainguard | superset-6.1 | 0, 0, 0 |
| chainguard | open-webui | 0, 0, 0 |
| python-pillow | Pillow | |
| chainguard | mlflow | 0, 0, 0 |
…and 2 more
Timeline
- Jul 14, 2026 Coalition ESS Score
- Jul 14, 2026 CVE Published
- Aug 7, 2026 EPSS Score
- Aug 14, 2026 Security Advisory
- Aug 27, 2026 EPSS Score
- Sep 1, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
References
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6 x_refsource_CONFIRM
- https://github.com/python-pillow/Pillow/pull/9715 x_refsource_MISC
- https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721 x_refsource_MISC
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-59205 advisory
- https://github.com/advisories/GHSA-9hw9-ch79-4vh6 advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3453.yaml advisory