StackRadar

CVE-2020-5313

High

Advisory

Published 3 Jan 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.028
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
17
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
2 of 2
affected packages

Out-of-bounds Read in Pillow

Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+4 more6.2.218
pillowdeb5.1.0-15.1.0-1ubuntu0.21
OSV records
GHSA-hj69-c76v-86wrUBUNTU-CVE-2020-5313
Also known as
BIT-pillow-2020-5313, PYSEC-2020-84, USN-4272-1

Charts affected

17 by stars
ChartLatestAffected imagesRadar Score
deconzgeek-cookbookVerified publisher6.5.21 of 1See more

deconz geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.12.066541bbb78952
pillow@5.4.1
6.2.2

Open the chart page →

3,555
esphomegeek-cookbookVerified publisher8.4.21 of 1See more

esphome geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
esphome/esphome:1.18.03f51ec10e823
pillow@5.4.1
6.2.2

Open the chart page →

3,717
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
apsl/thumbor:6.7.051e2de5c2c70
pillow@5.4.1
6.2.2

Open the chart page →

38,346
helm-taigamvitale1989-helm-taigaVerified publisher0.2.51 of 2See more

helm-taiga mvitale1989-helm-taiga 0.2.5

1 of the 2 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pillow@4.3.0
6.2.2

Open the chart page →

5,104
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0
6.2.2

Open the chart page →

13,541
couchpotatobryanalves0.3.01 of 1See more

couchpotato bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pillow@6.2.1
6.2.2

Open the chart page →

2,018
sickchillbryanalves0.3.01 of 1See more

sickchill bryanalves 0.3.0

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pillow@6.2.1
6.2.2

Open the chart page →

2,504
check-mkcloudnativeapp0.2.11 of 1See more

check-mk cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
nlmacamp/check_mk:latest5dbb8589f824
pillow@5.0.0
6.2.2

Open the chart page →

2,408
daskcloudnativeapp2.2.12 of 2See more

dask cloudnativeapp 2.2.1

2 of the 2 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
pillow@5.3.0
6.2.2
daskdev/dask-notebook:1.1.0052630f5ca04
pillow@5.4.1
6.2.2

Open the chart page →

29,901
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pillow@5.0.0
6.2.2

Open the chart page →

77,758
webpagetest-servercloudnativeapp0.2.11 of 1See more

webpagetest-server cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
timothyclarke/wptserver:2018-03-0840a80ced8031
pillow@2.6.1
6.2.2

Open the chart page →

3,716
couchpotatocronce0.0.11 of 1See more

couchpotato cronce 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pillow@5.4.1
6.2.2

Open the chart page →

3,871
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
pillow@5.1.0
5.1.0-1ubuntu0.2
6.2.2

Open the chart page →

27,728
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0
6.2.2

Open the chart page →

13,551
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
6.2.2

Open the chart page →

55,726
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
pillow@5.4.1
6.2.2

Open the chart page →

27,633
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2020-5313.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
pillow@5.4.1
6.2.2

Open the chart page →

8,694

Container images carrying it

18 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apsl/thumbor:6.7.051e2de5c2c70
pillow@5.4.1
6.2.2
1
daskdev/dask:1.1.04ecd7bc35500
pillow@5.3.0
6.2.2
1
daskdev/dask-notebook:1.1.0052630f5ca04
pillow@5.4.1
6.2.2
1
deconzcommunity/deconz:2.12.066541bbb78952
pillow@5.4.1
6.2.2
1
esphome/esphome:1.18.03f51ec10e823
pillow@5.4.1
6.2.2
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pillow@5.4.1
6.2.2
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pillow@6.2.1
6.2.2
1
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0
6.2.2
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0
6.2.2
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pillow@6.2.1
6.2.2
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pillow@4.3.0
6.2.2
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
6.2.2
1
nlmacamp/check_mk:latest5dbb8589f824
pillow@5.0.0
6.2.2
1
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
pillow@5.1.0
5.1.0-1ubuntu0.2
6.2.2
1
scrapinghub/splash:3.4.1a5f89bc84606
pillow@5.4.1
6.2.2
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pillow@5.0.0
6.2.2
1
timothyclarke/wptserver:2018-03-0840a80ced8031
pillow@2.6.1
6.2.2
1
weblate/weblate:3.11.3-182848df56ecd
pillow@5.4.1
6.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.