---
schema_version: '1.0'
id: security-20260716-51776c
url: https://osv.dev/vulnerability/PYSEC-2026-3453
url_hash: 51776c86f80c12c410ad25337a0f14f9f84a17cc529489082ed32d48670c51fd
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-3453
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-59205
- PYSEC-2026-3453
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- pillow
- PyPI
lang: en
published_at: '2026-07-14T16:17:02Z'
fetched_at: '2026-07-16T06:46:04Z'
updated_at: '2026-07-16T06:46:07Z'
status: published
content_hash: 3953a5a5d90caccb1baf7a24f7bca692a519804c58d8b6c20a290b4f438602c9
license_note: full
summary: Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im,
  imOut) API can trigger controlled native heap corruption when the caller supplies
  an output image whose mode does not match the transform's declared output mode.
  This issue is fixed
summary_source: rss
summary_en: Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im,
  imOut) API can trigger controlled native heap corruption when the caller supplies
  an output image whose mode does not match the transform's declared output mode.
  This issue is fixed
entities:
- name: Pillow
  type: artifact
key_facts: []
related: []
related_auto: []
title: CVE-2026-59205 — pillow
---

# CVE-2026-59205 — pillow

## TL;DR
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed

## Key Points
- cve / CVE-2026-59205 / PYSEC-2026-3453 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H / pillow / PyPI

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
**Advisory:** PYSEC-2026-3453 (CVE-2026-59205)

**Affected (your watchlist):**
- `PyPI:pillow` 12.1.1 → fixed in 12.3.0 [docker/docker-llmwiki]
- `PyPI:pillow` 12.2.0 → fixed in 12.3.0 [docker/local+docker/mac]

**Details:**
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.

**References:**
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0
- https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721
- https://github.com/python-pillow/Pillow/pull/9715
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-3453_

## Source
元記事: [CVE-2026-59205 — pillow](https://osv.dev/vulnerability/PYSEC-2026-3453) — published 2026-07-14T16:17:02Z
