StackRadar

CVE-2019-16865

High

Advisory

Published 4 Oct 2019In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
2 of 2
affected packages

DOS attack in Pillow when processing specially crafted image files

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+3 more6.2.016
pillowdeb5.1.0-15.1.0-1ubuntu0.21
OSV records
GHSA-j7mj-748x-7p78UBUNTU-CVE-2019-16865
Also known as
PYSEC-2019-110, USN-4272-1

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
deconzgeek-cookbookVerified publisher6.5.21 of 1See more

deconz geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.12.066541bbb78952
pillow@5.4.1
6.2.0

Open the chart page →

3,555
esphomegeek-cookbookVerified publisher8.4.21 of 1See more

esphome geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
esphome/esphome:1.18.03f51ec10e823
pillow@5.4.1
6.2.0

Open the chart page →

3,717
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
apsl/thumbor:6.7.051e2de5c2c70
pillow@5.4.1
6.2.0

Open the chart page →

38,346
helm-taigamvitale1989-helm-taigaVerified publisher0.2.51 of 2See more

helm-taiga mvitale1989-helm-taiga 0.2.5

1 of the 2 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pillow@4.3.0
6.2.0

Open the chart page →

5,104
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0
6.2.0

Open the chart page →

13,541
check-mkcloudnativeapp0.2.11 of 1See more

check-mk cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
nlmacamp/check_mk:latest5dbb8589f824
pillow@5.0.0
6.2.0

Open the chart page →

2,408
daskcloudnativeapp2.2.12 of 2See more

dask cloudnativeapp 2.2.1

2 of the 2 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
pillow@5.3.0
6.2.0
daskdev/dask-notebook:1.1.0052630f5ca04
pillow@5.4.1
6.2.0

Open the chart page →

29,901
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pillow@5.0.0
6.2.0

Open the chart page →

77,758
webpagetest-servercloudnativeapp0.2.11 of 1See more

webpagetest-server cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
timothyclarke/wptserver:2018-03-0840a80ced8031
pillow@2.6.1
6.2.0

Open the chart page →

3,716
couchpotatocronce0.0.11 of 1See more

couchpotato cronce 0.0.1

1 of the 1 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pillow@5.4.1
6.2.0

Open the chart page →

3,871
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
pillow@5.1.0
5.1.0-1ubuntu0.2
6.2.0

Open the chart page →

27,728
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0
6.2.0

Open the chart page →

13,551
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
6.2.0

Open the chart page →

55,726
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
pillow@5.4.1
6.2.0

Open the chart page →

27,633
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2019-16865.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
pillow@5.4.1
6.2.0

Open the chart page →

8,694

Container images carrying it

16 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apsl/thumbor:6.7.051e2de5c2c70
pillow@5.4.1
6.2.0
1
daskdev/dask:1.1.04ecd7bc35500
pillow@5.3.0
6.2.0
1
daskdev/dask-notebook:1.1.0052630f5ca04
pillow@5.4.1
6.2.0
1
deconzcommunity/deconz:2.12.066541bbb78952
pillow@5.4.1
6.2.0
1
esphome/esphome:1.18.03f51ec10e823
pillow@5.4.1
6.2.0
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pillow@5.4.1
6.2.0
1
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0
6.2.0
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0
6.2.0
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pillow@4.3.0
6.2.0
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
6.2.0
1
nlmacamp/check_mk:latest5dbb8589f824
pillow@5.0.0
6.2.0
1
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
pillow@5.1.0
5.1.0-1ubuntu0.2
6.2.0
1
scrapinghub/splash:3.4.1a5f89bc84606
pillow@5.4.1
6.2.0
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pillow@5.0.0
6.2.0
1
timothyclarke/wptserver:2018-03-0840a80ced8031
pillow@2.6.1
6.2.0
1
weblate/weblate:3.11.3-182848df56ecd
pillow@5.4.1
6.2.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.