---
schema_version: '1.0'
id: security-20260716-ec2875
url: https://osv.dev/vulnerability/PYSEC-2026-3451
url_hash: ec28753d37bb27a03a10713c995d5d7f351f6317e71e9c25c63b5fc43f1a34a7
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-3451
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-59199
- PYSEC-2026-3451
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- pillow
- PyPI
lang: en
published_at: '2026-07-14T16:17:01Z'
fetched_at: '2026-07-16T06:46:04Z'
updated_at: '2026-07-16T06:46:07Z'
status: published
content_hash: b087c65760a32666be47c9ef8d0af5cbc89b626ed8272ed5ac30063101c45516
license_note: full
summary: Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image
  coordinate APIs can trigger a native heap out-of-bounds write when given coordinates
  near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite().
  This issue is fixed in v
summary_source: rss
summary_en: Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image
  coordinate APIs can trigger a native heap out-of-bounds write when given coordinates
  near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite().
  This issue is fixed in v
entities:
- name: Pillow
  type: artifact
key_facts: []
related: []
related_auto: []
title: CVE-2026-59199 — pillow
---

# CVE-2026-59199 — pillow

## TL;DR
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in v

## Key Points
- cve / CVE-2026-59199 / PYSEC-2026-3451 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H / pillow / PyPI

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
**Advisory:** PYSEC-2026-3451 (CVE-2026-59199)

**Affected (your watchlist):**
- `PyPI:pillow` 12.1.1 → fixed in 12.3.0 [docker/docker-llmwiki]
- `PyPI:pillow` 12.2.0 → fixed in 12.3.0 [docker/local+docker/mac]

**Details:**
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.

**References:**
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0
- https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b
- https://github.com/python-pillow/Pillow/pull/9703
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-3451_

## Source
元記事: [CVE-2026-59199 — pillow](https://osv.dev/vulnerability/PYSEC-2026-3451) — published 2026-07-14T16:17:01Z
