High severity7.5NVD Advisory· Published Jul 14, 2026· Updated Jul 14, 2026
CVE-2026-59205
CVE-2026-59205
Description
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pillowPyPI | < 12.3.0 | 12.3.0 |
Affected products
21- Range: <12.3.0
- osv-coords18 versionspkg:apk/chainguard/label-studiopkg:apk/chainguard/lmcache-cuda-12.8pkg:apk/chainguard/mlflowpkg:apk/chainguard/openstack-horizon-2025.2pkg:apk/chainguard/openstack-horizon-2025.2-fipspkg:apk/chainguard/openstack-horizon-2026.1pkg:apk/chainguard/openstack-horizon-2026.1-fipspkg:apk/chainguard/superset-6.0pkg:apk/chainguard/superset-6.1pkg:apk/chainguard/superset-fips-6.1pkg:apk/chainguard/tensorflow-gpu-jupyterpkg:apk/chainguard/text-generation-inferencepkg:apk/chainguard/tritonserver-backend-vllm-cuda-13.0pkg:apk/wolfi/mlflowpkg:apk/wolfi/superset-6.0pkg:apk/wolfi/superset-6.1pkg:bitnami/pillowpkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Leap%2016.0
< 1.23.0-r11+ 17 more
- (no CPE)range: < 1.23.0-r11
- (no CPE)range: < 0.5.3-r0
- (no CPE)range: < 3.14.0-r2
- (no CPE)range: < 25.5.2_git20260617-r4
- (no CPE)range: < 25.5.2_git20260617-r5
- (no CPE)range: < 25.7.3_git20260630-r2
- (no CPE)range: < 25.7.3_git20260630-r2
- (no CPE)range: < 6.0.0-r13
- (no CPE)range: < 6.1.0-r6
- (no CPE)range: < 6.1.0-r5
- (no CPE)range: < 2.21.0-r7
- (no CPE)range: < 3.3.7-r20
- (no CPE)range: < 25.11-r11
- (no CPE)range: < 3.14.0-r2
- (no CPE)range: < 6.0.0-r13
- (no CPE)range: < 6.1.0-r6
- (no CPE)range: < 12.3.0
- (no CPE)range: < 11.3.0-160000.8.1
Patches
Vulnerability mechanics
References
7- github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721nvdPatchWEB
- github.com/python-pillow/Pillow/pull/9715nvdIssue TrackingPatchWEB
- github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-9hw9-ch79-4vh6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59205ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-3453.yamlghsaWEB
- github.com/python-pillow/Pillow/releases/tag/12.3.0nvdRelease NotesWEB
News mentions
1- Pillow: Four Denial-of-Service Vulnerabilities Disclosed Together for Python Imaging LibraryVypr Intelligence · Jul 16, 2026