BIT-pillow-2026-42309

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/pillow/BIT-pillow-2026-42309.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-pillow-2026-42309
Aliases
Published
2026-05-12T08:54:03.041Z
Modified
2026-05-12T10:56:10.762688645Z
Summary
Pillow: Heap buffer overflow with nested list coordinates
Details

Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This issue has been patched in version 12.2.0.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:python:pillow:*:*:*:*:*:python:*:*"
    ]
}
References

Affected packages

Bitnami / pillow

Package

Name
pillow
Purl
pkg:bitnami/pillow

Severity

  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
11.2.1
Fixed
12.2.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/pillow/BIT-pillow-2026-42309.json"