Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59197

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
Версия до 12.3.0 (исключая)

EPSS

Процентиль: 32%
0.00397
Низкий

8.2 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 8.2
ubuntu
20 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.

CVSS3: 8.2
redhat
20 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.

CVSS3: 8.2
debian
20 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public r ...

CVSS3: 8.2
github
14 дней назад

Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

oracle-oval
5 дней назад

ELSA-2026-48021: python-pillow security update (IMPORTANT)

EPSS

Процентиль: 32%
0.00397
Низкий

8.2 High

CVSS3

Дефекты

CWE-190