Feed/CVE-2026-59204
CVE-2026-59204HIGHCVSS 0.0

CVE-2026-59204

Published Jul 14, 2026·Updated Jul 20, 2026

NVD Description

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.

Affected Packages (1)

pillowPYPI
From 8.2.0
Fixed in 12.3.0

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free