BIT-pillow-2026-54058

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/pillow/BIT-pillow-2026-54058.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-pillow-2026-54058
Aliases
Published
2026-07-19T23:50:11Z
Modified
2026-09-10T16:01:21Z
Summary
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
Details

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:python:pillow:*:*:*:*:*:python:*:*"
    ],
    "severity":  "Critical"
}
References

Affected packages

Bitnami / pillow

Package

Name
pillow
Purl
pkg:bitnami/pillow

Severity

  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
12.3.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/pillow/BIT-pillow-2026-54058.json"