Pillow
Vendor:
First CVE: Apr 17, 2014 · Active for 12 years
72
Total CVEs
More Total CVEs than 99% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pillow over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 17, 2014
12 years ago
Most Recent CVE
Jul 14, 2026
13 days ago
CVE Severity & Scoring
Pillow72 CVEs
33%
51%
14%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local15 (20.8%)
Network51 (70.8%)
Unknown6 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (86.1%)
High4 (5.6%)
Unknown6 (8.3%)
User Interaction
None46 (63.9%)
Unknown6 (8.3%)
Required20 (27.8%)
Privileges Required
Low4 (5.6%)
High0 (0.0%)
None62 (86.1%)
Unknown6 (8.3%)
Top CVEs
Signals from CVEs in this product scope (72 CVEs).
72 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59197HIGH Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because I | Jul 14, 2026 | 8.2 | 36 | NO | NO |
CVE-2016-4009CRITICAL Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of | Apr 13, 2016 | 9.8 | 35 | NO | NO |
CVE-2026-54060HIGH Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) withou | Jul 6, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-42311HIGH Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash | May 9, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-59200HIGH Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length fiel | Jul 14, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-59205HIGH Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies | Jul 14, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-59204HIGH Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of reco | Jul 14, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-55379HIGH Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimension | Jul 6, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-55380HIGH Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calli | Jul 6, 2026 | 7.5 | 33 | NO | NO |
CVE-2022-22817CRITICAL PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used. | Jan 10, 2022 | 9.8 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (72 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (72 CVEs).
Media Mentions
Signals from CVEs in this product scope (72 CVEs).
Top CNAs Publishing CVEs For Pillow
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1.0 | 1 | 9.8 | 2.3% | 0 | 0 |
| 3.1.0 | 1 | 5.5 | 2.6% | 0 | 0 |
| 3.0.0 | 1 | 5.5 | 2.6% | 0 | 0 |
| 2.9.0 | 1 | 5.5 | 2.6% | 0 | 0 |
| 2.8.2 | 1 | 5.5 | 2.6% | 0 | 0 |
| 2.8.1 | 1 | 5.5 | 2.6% | 0 | 0 |
| 2.8.0 | 1 | 5.5 | 2.6% | 0 | 0 |
| 2.7.0 | 1 | 5.5 | 2.6% | 0 | 0 |
| 2.6.2 | 1 | 5.5 | 2.6% | 0 | 0 |
| 2.6.1 | 1 | 5.5 | 2.6% | 0 | 0 |
| 2.6.0 | 1 | 5.5 | 2.6% | 0 | 0 |
| 2.5.3 | 1 | 5.5 | 2.6% | 0 | 0 |
| 2.5.2 | 2 | 5.3 | 2.9% | 0 | 0 |
| 2.5.1 | 2 | 5.3 | 2.9% | 0 | 0 |
| 2.5.0 | 2 | 5.3 | 2.9% | 0 | 0 |
| 2.3.0 | 2 | 7.5 | 7.5% | 0 | 0 |
| 11.2.1 | 1 | 5.5 | 0.3% | 0 | 0 |