VYPR
High severity7.5NVD Advisory· Published Jul 14, 2026· Updated Jul 21, 2026

CVE-2026-59204

CVE-2026-59204

Description

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pillowPyPI
>= 8.2.0, < 12.3.012.3.0

Affected products

21

Patches

Vulnerability mechanics

References

6

News mentions

1