Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59204

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
Версия от 8.2.0 (включая) до 12.3.0 (исключая)

EPSS

Процентиль: 32%
0.00398
Низкий

7.5 High

CVSS3

Дефекты

CWE-789
CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
18 дней назад

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.

CVSS3: 7.5
redhat
18 дней назад

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.

CVSS3: 7.5
debian
18 дней назад

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/lib ...

github
12 дней назад

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

CVSS3: 7.5
fstec
около 1 месяца назад

Уязвимость файла src/libImaging/Jpeg2KDecode.c библиотеки для работы с изображениями Pillow, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 32%
0.00398
Низкий

7.5 High

CVSS3

Дефекты

CWE-789
CWE-770