VYPR
High severity7.5NVD Advisory· Published Jul 14, 2026· Updated Jul 14, 2026

CVE-2026-59205

CVE-2026-59205

Description

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pillowPyPI
< 12.3.012.3.0

Affected products

21

Patches

Vulnerability mechanics

References

7

News mentions

1