High severity7.5NVD Advisory· Published Jul 14, 2026· Updated Jul 21, 2026
CVE-2026-59204
CVE-2026-59204
Description
Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pillowPyPI | >= 8.2.0, < 12.3.0 | 12.3.0 |
Affected products
21- osv-coords19 versionspkg:apk/chainguard/label-studiopkg:apk/chainguard/lmcache-cuda-12.8pkg:apk/chainguard/superset-6.1pkg:apk/chainguard/superset-fips-6.1pkg:apk/chainguard/tritonserver-backend-vllm-cuda-13.0pkg:apk/wolfi/superset-6.0pkg:apk/chainguard/tensorflow-gpu-jupyterpkg:apk/wolfi/superset-6.1pkg:apk/chainguard/openstack-horizon-2026.1pkg:apk/chainguard/mlflowpkg:apk/chainguard/openstack-horizon-2026.1-fipspkg:bitnami/pillowpkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Tumbleweedpkg:apk/chainguard/openstack-horizon-2025.2pkg:apk/chainguard/superset-6.0pkg:apk/chainguard/text-generation-inferencepkg:apk/chainguard/openstack-horizon-2025.2-fipspkg:apk/wolfi/mlflow
< 1.23.0-r11+ 18 more
- (no CPE)range: < 1.23.0-r11
- (no CPE)range: < 0.5.3-r0
- (no CPE)range: < 6.1.0-r6
- (no CPE)range: < 6.1.0-r5
- (no CPE)range: < 25.11-r11
- (no CPE)range: < 6.0.0-r13
- (no CPE)range: < 2.21.0-r7
- (no CPE)range: < 6.1.0-r6
- (no CPE)range: < 25.7.3_git20260630-r2
- (no CPE)range: < 3.14.0-r2
- (no CPE)range: < 25.7.3_git20260630-r2
- (no CPE)range: >= 8.2.0, < 12.3.0
- (no CPE)range: < 11.3.0-160000.8.1
- (no CPE)range: < 12.3.0-2.1
- (no CPE)range: < 25.5.2_git20260617-r4
- (no CPE)range: < 6.0.0-r13
- (no CPE)range: < 3.3.7-r20
- (no CPE)range: < 25.5.2_git20260617-r5
- (no CPE)range: < 3.14.0-r2
8.2.0 - 12.2.0+ 1 more
- (no CPE)range: 8.2.0 - 12.2.0
- cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*range: >=8.2.0,<12.3.0
Patches
Vulnerability mechanics
References
6- github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11canvdPatchWEB
- github.com/python-pillow/Pillow/pull/9704nvdExploitIssue TrackingPatchWEB
- github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44jnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-vjc4-5qp5-m44jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59204ghsaADVISORY
- github.com/python-pillow/Pillow/releases/tag/12.3.0nvdRelease NotesWEB
News mentions
1- Pillow: Four Denial-of-Service Vulnerabilities Disclosed Together for Python Imaging LibraryVypr Intelligence · Jul 16, 2026