StackRadar

CVE-2023-44271

High

Advisory

Published 3 Nov 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
67
of 17,781 indexed, latest versions
Container images
67
deployed by those charts
Fix available
2 of 2
affected packages

Pillow Denial of Service vulnerability

Carried by container images the latest versions of 67 of 17,781 indexed charts deploy, on 67 images.

Affected packageAffected versionsFixed inImages
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+20 more10.0.067
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.4.0-1.1+b15.1.0-1ubuntu0.8+esm2, 7.0.0-4ubuntu0.8, 9.4.0-1.1+deb12u15
OSV records
DEBIAN-CVE-2023-44271GHSA-8ghj-p4vj-mr35UBUNTU-CVE-2023-44271
Also known as
BIT-pillow-2023-44271, PYSEC-2023-227, USN-6618-1, USN-8135-1

Charts affected

67 by stars
ChartLatestAffected imagesRadar Score
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pillow@8.3.1
10.0.0

Open the chart page →

24,293
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
pillow@7.2.0
10.0.0

Open the chart page →

7,984
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
10.0.0

Open the chart page →

6,501
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
pillow@9.4.0
10.0.0

Open the chart page →

10,780
frigatek8s-home-lab-repo9.1.11 of 1See more

frigate k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@8.1.2
10.0.0

Open the chart page →

2,370
exposureloglsst-sqre0.2.11 of 1See more

exposurelog lsst-sqre 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
lsstsqre/exposurelog:0.8.079b00fb67a65
pillow@9.0.1
10.0.0

Open the chart page →

2,078
mlflowmondata-helm-chartsVerified publisher0.2.31 of 1See more

mlflow mondata-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pillow@9.5.0
10.0.0

Open the chart page →

3,811
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pillow@8.4.0
10.0.0

Open the chart page →

8,556
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
pillow@9.4.0
10.0.0

Open the chart page →

5,456
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
10.0.0

Open the chart page →

55,726
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
pillow@5.4.1
10.0.0

Open the chart page →

27,633
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
pillow@9.2.0
10.0.0

Open the chart page →

22,084
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
pillow@9.4.0
10.0.0

Open the chart page →

7,685
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
pillow@5.4.1
10.0.0

Open the chart page →

8,694
frigatesmarthallVerified publisher1.0.61 of 1See more

frigate smarthall 1.0.6

1 of the 1 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pillow@8.1.2
10.0.0

Open the chart page →

2,243
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pillow@8.4.0
10.0.0

Open the chart page →

8,715
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44271.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
pillow@9.4.0
10.0.0

Open the chart page →

3,164

Container images carrying it

67 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
10.0.0
3
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@8.1.2
10.0.0
2
weblate/weblate:4.2.2-169c160d37a3c
pillow@7.2.0
10.0.0
2
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
pillow@9.4.0
10.0.0
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
pillow@9.4.0
10.0.0
1
anujdatar/cups:25.07.01685df04a643b
pillow@9.4.0
10.0.0
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
pillow@9.1.0
10.0.0
1
apsl/thumbor:6.7.051e2de5c2c70
pillow@5.4.1
10.0.0
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pillow@9.5.0
10.0.0
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
pillow@7.0.0-4ubuntu0.5
pillow@8.1.0
7.0.0-4ubuntu0.8
10.0.0
1
buntha/mlflow:2.1.1154542cc3083
pillow@9.3.0
10.0.0
1
camerahub/camerahub:0.36.23a5af37dd6e1b
pillow@9.5.0
10.0.0
1
daskdev/dask:1.1.04ecd7bc35500
pillow@5.3.0
10.0.0
1
daskdev/dask-notebook:1.1.0052630f5ca04
pillow@5.4.1
10.0.0
1
deconzcommunity/deconz:2.29.2062de2362641
pillow@9.4.0
10.0.0
1
deconzcommunity/deconz:2.12.066541bbb78952
pillow@5.4.1
10.0.0
1
dpage/pgadmin4:7.537946e4f3e7b
pillow@9.5.0
10.0.0
1
esphome/esphome:1.18.03f51ec10e823
pillow@5.4.1
10.0.0
1
evk02/mlflow:2.2.1ef6ff257ef35
pillow@9.4.0
10.0.0
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pillow@9.3.0
10.0.0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
pillow@7.2.0
10.0.0
1
hhyo/archery:v1.9.11aa41843419e
pillow@9.0.1
10.0.0
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
pillow@8.4.0
10.0.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
10.0.0
1
kobotoolbox/kobocat:2.022.24ab15679454415
pillow@9.1.0
10.0.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pillow@9.1.0
10.0.0
1
linuxserver/babybuddy:1.10.2f7d7c7704249
pillow@9.0.1
10.0.0
1
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
10.0.0
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pillow@5.4.1
10.0.0
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pillow@6.2.1
10.0.0
1
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0-1ubuntu0.6
pillow@5.1.0
5.1.0-1ubuntu0.8+esm2
10.0.0
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
pillow@5.1.0
5.1.0-1ubuntu0.8+esm2
10.0.0
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
pillow@8.2.0
10.0.0
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pillow@6.2.1
10.0.0
1
lsstsqre/exposurelog:0.8.079b00fb67a65
pillow@9.0.1
10.0.0
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pillow@9.0.1
10.0.0
1
matrixdotorg/synapse:v1.78.0def97fd537d8
pillow@9.4.0
10.0.0
1
mcronce/yadms-ftp:latestf820ef2e3c26
pillow@7.0.0
10.0.0
1
mcronce/yadms-web:latestc03c1c7f5aa9
pillow@7.0.0
10.0.0
1
mide/minecraft-overviewer:latest4eee0dcb715f
pillow@8.1.2
10.0.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pillow@9.5.0
10.0.0
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pillow@8.4.0
10.0.0
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pillow@4.3.0
10.0.0
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
10.0.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
pillow@9.2.0
10.0.0
1
nlmacamp/check_mk:latest5dbb8589f824
pillow@5.0.0
10.0.0
1
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
pillow@5.1.0
5.1.0-1ubuntu0.8+esm2
10.0.0
1
opendatacube/wps:latest80df355a660b
pillow@9.0.1
10.0.0
1
robmarkcole/deepstack-ui:latest410275726459
pillow@8.3.2
10.0.0
1
scrapinghub/splash:3.4.1a5f89bc84606
pillow@5.4.1
10.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.