Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-pillow-docUpgrade python-pillow-develUpgrade python-pillow-tkUpgrade python-pillow-saneUpgrade python-pillowUpgrade python-pillow-debuginfo | Aug 5, 2026 | Aug 5, 2026 |
| Amazon_linux_2023 | — | Upgrade python3-pillow-tk-debuginfoUpgrade python3-pillow-tkUpgrade python-pillow-debugsourceUpgrade python3-pillow-debuginfoUpgrade python-pillow-debuginfoUpgrade python3-pillowUpgrade python3-pillow-devel | Aug 10, 2026 | Jul 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub