An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2kugrayi.
{ "cpes": [ "cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*" ], "severity": "Critical" }
"https://github.com/bitnami/vulndb/tree/main/data/pillow/BIT-pillow-2021-25288.json"