Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59199

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
Версия до 12.3.0 (исключая)

EPSS

Процентиль: 31%
0.00385
Низкий

7.5 High

CVSS3

Дефекты

CWE-190
CWE-787

Связанные уязвимости

CVSS3: 7.5
ubuntu
20 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.

CVSS3: 7.5
redhat
20 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.

CVSS3: 7.5
debian
20 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public ima ...

CVSS3: 7.5
github
14 дней назад

Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

suse-cvrf
18 дней назад

Security update for python-Pillow

EPSS

Процентиль: 31%
0.00385
Низкий

7.5 High

CVSS3

Дефекты

CWE-190
CWE-787