Medium severity6.5NVD Advisory· Published Jul 14, 2026· Updated Jul 14, 2026
CVE-2026-59198
CVE-2026-59198
Description
Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
PillowPyPI | >= 5.2.0, < 12.3.0 | 12.3.0 |
Affected products
21- osv-coords19 versionspkg:apk/chainguard/label-studiopkg:apk/chainguard/lmcache-cuda-12.8pkg:apk/chainguard/mlflowpkg:apk/chainguard/openstack-horizon-2025.2pkg:apk/chainguard/openstack-horizon-2025.2-fipspkg:apk/chainguard/openstack-horizon-2026.1pkg:apk/chainguard/openstack-horizon-2026.1-fipspkg:apk/chainguard/superset-6.0pkg:apk/chainguard/superset-6.1pkg:apk/chainguard/superset-fips-6.1pkg:apk/chainguard/tensorflow-gpu-jupyterpkg:apk/chainguard/text-generation-inferencepkg:apk/chainguard/tritonserver-backend-vllm-cuda-13.0pkg:apk/wolfi/mlflowpkg:apk/wolfi/superset-6.0pkg:apk/wolfi/superset-6.1pkg:bitnami/pillowpkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Tumbleweed
< 1.23.0-r11+ 18 more
- (no CPE)range: < 1.23.0-r11
- (no CPE)range: < 0.5.3-r0
- (no CPE)range: < 3.14.0-r2
- (no CPE)range: < 25.5.2_git20260617-r4
- (no CPE)range: < 25.5.2_git20260617-r5
- (no CPE)range: < 25.7.3_git20260630-r2
- (no CPE)range: < 25.7.3_git20260630-r2
- (no CPE)range: < 6.0.0-r13
- (no CPE)range: < 6.1.0-r6
- (no CPE)range: < 6.1.0-r5
- (no CPE)range: < 2.21.0-r7
- (no CPE)range: < 3.3.7-r20
- (no CPE)range: < 25.11-r11
- (no CPE)range: < 3.14.0-r2
- (no CPE)range: < 6.0.0-r13
- (no CPE)range: < 6.1.0-r6
- (no CPE)range: >= 5.2.0, < 12.3.0
- (no CPE)range: < 11.3.0-160000.8.1
- (no CPE)range: < 12.3.0-2.1
Patches
Vulnerability mechanics
References
6- github.com/python-pillow/Pillow/commit/eada3cbd7fb9963ee90673fb7b5270124a0d5f4bnvdPatchWEB
- github.com/python-pillow/Pillow/pull/9709nvdIssue TrackingPatchWEB
- github.com/python-pillow/Pillow/security/advisories/GHSA-fj7v-r99m-22gqnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-fj7v-r99m-22gqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59198ghsaADVISORY
- github.com/python-pillow/Pillow/releases/tag/12.3.0nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.