7.5

CVE-2026-59205

Exploit

Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Pillow Version < 12.3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.311
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://github.com/python-pillow/Pillow/releases/tag/12.3.0
Release Notes
https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721
Patch
https://github.com/python-pillow/Pillow/pull/9715
Patch
Issue Tracking
https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6
Vendor Advisory
Exploit