The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
"https://github.com/pypa/advisory-database/blob/main/vulns/pillow/PYSEC-2021-317.yaml"