CVE-2019-16865
HighAdvisory
Published 4 Oct 2019In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.032
- 87th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 15
- of 17,781 indexed, latest versions
- Container images
- 16
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
DOS attack in Pillow when processing specially crafted image files
Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 16 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pillowpypi | 2.6.1, 4.3.0, 5.0.0, 5.1.0+3 more | 6.2.0 | 16 |
| pillowdeb | 5.1.0-1 | 5.1.0-1ubuntu0.2 | 1 |
- OSV records
- GHSA-j7mj-748x-7p78UBUNTU-CVE-2019-16865
- Also known as
- PYSEC-2019-110, USN-4272-1
Charts affected
15 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| deconzgeek-cookbookVerified publisher | 6.5.2 | 1 of 1See more | 3,555 |
| esphomegeek-cookbookVerified publisher | 8.4.2 | 1 of 1See more | 3,717 |
| data-fairdata354-helmVerified publisher | 1.1.2 | 1 of 12See more | 38,346 |
| helm-taigamvitale1989-helm-taigaVerified publisher | 0.2.5 | 1 of 2See more | 5,104 |
| delugerubxkubeVerified publisher | 1.2.1 | 1 of 1See more | 13,541 |
| check-mkcloudnativeapp | 0.2.1 | 1 of 1See more | 2,408 |
| daskcloudnativeapp | 2.2.1 | 2 of 2See more | 29,901 |
| webpagetest-agentcloudnativeapp | 0.2.0 | 1 of 1See more | 77,758 |
| webpagetest-servercloudnativeapp | 0.2.1 | 1 of 1See more | 3,716 |
| couchpotatocronce | 0.0.1 | 1 of 1See more | 3,871 |
| datacubedatacube-charts | 0.18.2 | 1 of 1See more | 27,728 |
| delugegeek-cookbookVerified publisher | 5.4.2 | 1 of 1See more | 13,551 |
| polyglotncsaVerified publisher | 0.1.1 | 1 of 18See more | 55,726 |
| splashntppoolVerified publisher | 1.0.4 | 1 of 1See more | 27,633 |
| weblateslamdev | 0.0.11 | 1 of 2See more | 8,694 |
Container images carrying it
16 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| apsl/ | 51e2de5c2c70 | pillow | 6.2.0 | 1 |
| daskdev/ | 4ecd7bc35500 | pillow | 6.2.0 | 1 |
| daskdev/ | 052630f5ca04 | pillow | 6.2.0 | 1 |
| deconzcommunity/ | 6541bbb78952 | pillow | 6.2.0 | 1 |
| esphome/ | 3f51ec10e823 | pillow | 6.2.0 | 1 |
| linuxserver/ | 89cd8d5fb1ac | pillow | 6.2.0 | 1 |
| linuxserver/ | 0ac871624394 | pillow | 6.2.0 | 1 |
| linuxserver/ | 2ce561a95e7b | pillow | 6.2.0 | 1 |
| mvitale1989/ | 1504ccda06df | pillow | 6.2.0 | 1 |
| ncsapolyglot/ | 438d82cdbdb5 | pillow | 6.2.0 | 1 |
| nlmacamp/ | 5dbb8589f824 | pillow | 6.2.0 | 1 |
| opendatacube/ | 1b90cdf68831 | pillow pillow | 5.1.0-1ubuntu0.2 6.2.0 | 1 |
| scrapinghub/ | a5f89bc84606 | pillow | 6.2.0 | 1 |
| timothyclarke/ | 22c41e5ca7e2 | pillow | 6.2.0 | 1 |
| timothyclarke/ | 40a80ced8031 | pillow | 6.2.0 | 1 |
| weblate/ | 82848df56ecd | pillow | 6.2.0 | 1 |