Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-28678

20
FAUCET Score

CVE-2021-28678 is a denial-of-service vulnerability affecting Pillow versions prior to 8.2.0, specifically impacting Fedora and Python Pillow products. The flaw stems from improper data read checks within the BlpImagePlugin when processing BLP data, allowing a decoder to run excessively on empty data. Rated as Medium severity (CVSS 5.5), it requires local access and user interaction (e.g., opening a malicious file) to achieve a high availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 8.2.0CPE matchmatch criteria
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
33CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.73%
Probability of exploitation in next 30 days
EPSS Percentile
50.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0073 is in the 57th percentile among its peer group of 5,765 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: PillowFixed in: 8.2.0
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python-pillow-0:5.1.1-16.el8
View patch
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8

Vendor Advisories (2)

pipGHSA-hjfx-8p6c-g7gxmedium

Insufficient Verification of Data Authenticity in Pillow

Jun 8, 2021
redhatCVE-2021-28678Moderate

python-pillow: Excessive looping in BLP image reader

Apr 1, 2021

References

github.com / python-pillow/Pillow/pull/5377
PatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MQHA5HAIBOYI3R6HDWCLAGFTIQP767FL
pillow.readthedocs.io / en/stable/releasenotes/8.2.0.html
Release NotesVendor Advisory
security.gentoo.org / glsa/202107-33
Third Party Advisory