Critical severity9.1NVD Advisory· Published Jul 14, 2026· Updated Aug 6, 2026
CVE-2026-54058
CVE-2026-54058
Description
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pillowPyPI | < 12.3.0 | 12.3.0 |
Affected products
25- osv-coords23 versionspkg:apk/chainguard/label-studiopkg:apk/chainguard/lmcache-cuda-12.8pkg:apk/chainguard/mlflowpkg:apk/chainguard/openstack-horizon-2025.2pkg:apk/chainguard/openstack-horizon-2025.2-fipspkg:apk/chainguard/openstack-horizon-2026.1pkg:apk/chainguard/openstack-horizon-2026.1-fipspkg:apk/chainguard/superset-6.0pkg:apk/chainguard/superset-6.1pkg:apk/chainguard/superset-fips-6.1pkg:apk/chainguard/tensorflow-gpu-jupyterpkg:apk/chainguard/text-generation-inferencepkg:apk/chainguard/tritonserver-backend-vllm-cuda-13.0pkg:apk/wolfi/mlflowpkg:apk/wolfi/superset-6.0pkg:apk/wolfi/superset-6.1pkg:bitnami/pillowpkg:rpm/almalinux/python3-pillowpkg:rpm/almalinux/python3-pillow-develpkg:rpm/almalinux/python3-pillow-docpkg:rpm/almalinux/python3-pillow-tkpkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Tumbleweed
< 1.23.0-r11+ 22 more
- (no CPE)range: < 1.23.0-r11
- (no CPE)range: < 0.5.3-r0
- (no CPE)range: < 3.14.0-r2
- (no CPE)range: < 25.5.2_git20260617-r4
- (no CPE)range: < 25.5.2_git20260617-r5
- (no CPE)range: < 25.7.3_git20260630-r2
- (no CPE)range: < 25.7.3_git20260630-r2
- (no CPE)range: < 6.0.0-r13
- (no CPE)range: < 6.1.0-r6
- (no CPE)range: < 6.1.0-r5
- (no CPE)range: < 2.21.0-r7
- (no CPE)range: < 3.3.7-r20
- (no CPE)range: < 25.11-r11
- (no CPE)range: < 3.14.0-r2
- (no CPE)range: < 6.0.0-r13
- (no CPE)range: < 6.1.0-r6
- (no CPE)range: < 12.3.0
- (no CPE)range: < 5.1.1-23.el8_10
- (no CPE)range: < 5.1.1-23.el8_10
- (no CPE)range: < 5.1.1-23.el8_10
- (no CPE)range: < 5.1.1-23.el8_10
- (no CPE)range: < 11.3.0-160000.8.1
- (no CPE)range: < 12.3.0-2.1
Patches
Vulnerability mechanics
References
6- github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90b3cfc1dnvdPatchWEB
- github.com/python-pillow/Pillow/pull/9719nvdIssue TrackingPatchWEB
- github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93nvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-62p4-gmf7-7g93ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-54058ghsaADVISORY
- github.com/python-pillow/Pillow/releases/tag/12.3.0nvdProductRelease NotesWEB
News mentions
0No linked articles in our index yet.