VYPR
High severity8.2NVD Advisory· Published Jul 14, 2026· Updated Jul 21, 2026

CVE-2026-59197

CVE-2026-59197

Description

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
PillowPyPI
< 12.3.012.3.0

Affected products

24

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.