---
title: 'Topic: pillow'
canonical_url: https://portal.chinng-lab-srv.dev/topics/pillow.md
content_kind: topic
updated_at: '2026-07-24T07:02:21Z'
---

# Topic: pillow

> Stable topic monitoring page generated from normalized published metadata.

- Canonical: https://portal.chinng-lab-srv.dev/topics/pillow.md
- Last updated: 2026-07-24T07:02:21Z
- Search: https://portal.chinng-lab-srv.dev/api/search?q=pillow
- MCP: portal_search(q="pillow")

## Related categories

- security/library

## Related entities

- CVE-2026-44243
- Ter Haibin Airport Bombing<br
- HigherDose
- Charles Hudson
- SparseAutoencoder
- Threads
- Latvia
- write-capable token
- Commander-in-chief
- Gtosocial_injection
- OpenAI
- wiki_upload
- Read
- Pillow
- HashMark
- https://deploymentsafety.openai.com/gpt-5-6/gpt-5-6.pdf
- HashTag
- Writer Ian Bogost
- Monaco bomb suspect

## Latest articles

- [CVE-2026-59200: Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()](https://portal.chinng-lab-srv.dev/security/library/security-20260724-bc2416.md): Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
- [CVE-2026-59204: Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service](https://portal.chinng-lab-srv.dev/security/library/security-20260724-51d556.md): Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
- [CVE-2026-59198: Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images](https://portal.chinng-lab-srv.dev/security/library/security-20260724-a8f0ed.md): Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
- [CVE-2026-54058: Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)](https://portal.chinng-lab-srv.dev/security/library/security-20260724-2a8214.md): Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
- [CVE-2026-59205: Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch](https://portal.chinng-lab-srv.dev/security/library/security-20260721-9c81bc.md): Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
- [CVE-2026-59204: Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service](https://portal.chinng-lab-srv.dev/security/library/security-20260721-e02209.md): Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
- [CVE-2026-59203: Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service](https://portal.chinng-lab-srv.dev/security/library/security-20260721-941bc6.md): Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
- [CVE-2026-59200: Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()](https://portal.chinng-lab-srv.dev/security/library/security-20260721-3aa418.md): Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
- [CVE-2026-59199: Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow](https://portal.chinng-lab-srv.dev/security/library/security-20260721-ca974b.md): Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
- [CVE-2026-59198: Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images](https://portal.chinng-lab-srv.dev/security/library/security-20260721-48da14.md): Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
- [CVE-2026-59197: Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`](https://portal.chinng-lab-srv.dev/security/library/security-20260721-871179.md): Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
- [CVE-2026-55798: Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path](https://portal.chinng-lab-srv.dev/security/library/security-20260721-054ec0.md): Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
- [CVE-2026-55380: Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`](https://portal.chinng-lab-srv.dev/security/library/security-20260721-4fa7c9.md): Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
- [CVE-2026-55379: Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading](https://portal.chinng-lab-srv.dev/security/library/security-20260721-d74706.md): Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
- [CVE-2026-54060: Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`](https://portal.chinng-lab-srv.dev/security/library/security-20260721-a1dd3d.md): Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
- [CVE-2026-54059: Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading](https://portal.chinng-lab-srv.dev/security/library/security-20260721-f6d04d.md): Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
- [CVE-2026-54058: Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)](https://portal.chinng-lab-srv.dev/security/library/security-20260721-6fab85.md): Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
- [CVE-2026-59197 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260723-e5b374.md): Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilt…
- [CVE-2026-59203 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260716-a3f93e.md): Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file…
- [CVE-2026-59205 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260716-51776c.md): Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image wh…
- [CVE-2026-59199 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260716-ec2875.md): Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in…
- [CVE-2026-42310: Pillow has a PDF Parsing Trailer Infinite Loop (DoS)](https://portal.chinng-lab-srv.dev/security/library/security-20260714-3d3887.md): Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
- [CVE-2026-55379 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-f7ab82.md): Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() wi…
- [CVE-2026-55798 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-e41644.md): Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the…
- [CVE-2026-55380 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-cb6737.md): Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompres…
- [CVE-2026-54060 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-3d7d29.md): Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._de…
- [CVE-2026-54059 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-27b2a1.md): Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without callin…
- [CVE-2026-42311 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-c572fa.md): Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code e…
- [CVE-2026-42309 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-388e4d.md): Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polyg…
- [CVE-2026-42308 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260711-dad7c4.md): Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer…
- [CVE-2026-42311: Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)](https://portal.chinng-lab-srv.dev/security/library/security-20260711-6ac13d.md): Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
- [CVE-2026-42310: Pillow has a PDF Parsing Trailer Infinite Loop (DoS)](https://portal.chinng-lab-srv.dev/security/library/security-20260711-96bbde.md): Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
- [CVE-2026-42308: Pillow has an integer overflow when processing fonts](https://portal.chinng-lab-srv.dev/security/library/security-20260711-202b54.md): Pillow has an integer overflow when processing fonts
- [CVE-2026-42309: Pillow has a heap buffer overflow with nested list coordinates](https://portal.chinng-lab-srv.dev/security/library/security-20260711-a57b4f.md): Pillow has a heap buffer overflow with nested list coordinates
- [CVE-2026-40192 — pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260714-f651a5.md): Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attac…
- [CVE-2026-40192: FITS GZIP decompression bomb in Pillow](https://portal.chinng-lab-srv.dev/security/library/security-20260711-42df7e.md): FITS GZIP decompression bomb in Pillow
