Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59197

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
Версия до 12.3.0 (исключая)

EPSS

Процентиль: 38%
0.00445
Низкий

8.2 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 8.2
ubuntu
2 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.

CVSS3: 8.2
redhat
2 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.

CVSS3: 8.2
debian
2 месяца назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public r ...

CVSS3: 8.2
github
2 месяца назад

Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

CVSS3: 8.2
fstec
2 месяца назад

Уязвимость функции ImageFilter.RankFilter.filter библиотеки для работы с изображениями Pillow, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

EPSS

Процентиль: 38%
0.00445
Низкий

8.2 High

CVSS3

Дефекты

CWE-190