Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59198

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 6.5
CVSS3: 7.5
EPSS Низкий

Описание

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
Версия от 5.2.0 (включая) до 12.3.0 (исключая)

EPSS

Процентиль: 23%
0.00313
Низкий

6.5 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 6.5
ubuntu
18 дней назад

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.

CVSS3: 6.5
redhat
18 дней назад

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.

CVSS3: 6.5
debian
18 дней назад

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's ...

CVSS3: 6.5
github
12 дней назад

Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

CVSS3: 6.5
fstec
около 1 месяца назад

Уязвимость функции ImagingTgaRleEncode() компонента TgaRleEncode.c библиотеки для работы с изображениями Pillow, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 23%
0.00313
Низкий

6.5 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-125
Уязвимость CVE-2026-59198