StackRadar

CVE-2024-28219

Medium

Advisory

Published 3 Apr 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.7
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
91
of 17,781 indexed, latest versions
Container images
91
deployed by those charts
Fix available
2 of 2
affected packages

Pillow buffer overflow vulnerability

Carried by container images the latest versions of 91 of 17,781 indexed charts deploy, on 91 images.

Affected packageAffected versionsFixed inImages
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+24 more10.3.091
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 5.4.1-2+deb10u1, 5.4.1-2+deb10u2+2 more5.1.0-1ubuntu0.8+esm1, 5.4.1-2+deb10u6, 7.0.0-4ubuntu0.9, 9.4.0-1.1+deb12u18
OSV records
DEBIAN-CVE-2024-28219GHSA-44wm-f244-xhp3UBUNTU-CVE-2024-28219DLA-3786-1
Also known as
BIT-pillow-2024-28219, PYSEC-2026-1793, USN-6744-1

Charts affected

91 by stars
ChartLatestAffected imagesRadar Score
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0
10.3.0

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0
10.3.0

Open the chart page →

5,974
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
pillow@9.0.1
10.3.0

Open the chart page →

6,172
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
pillow@9.3.0
10.3.0

Open the chart page →

14,856
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
pillow@9.3.0
10.3.0

Open the chart page →

25,122
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pillow@9.3.0
10.3.0

Open the chart page →

4,085
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
pillow@9.0.1
10.3.0

Open the chart page →

1,489
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
10.3.0

Open the chart page →

1,150
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
pillow@5.1.0
5.1.0-1ubuntu0.8+esm1
10.3.0

Open the chart page →

13,551
mylargeek-cookbookVerified publisher4.4.21 of 1See more

mylar geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
pillow@6.2.2
10.3.0

Open the chart page →

1,423
pyloadgeek-cookbookVerified publisher6.4.21 of 1See more

pyload geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/pyload:version-5de90278d3c87933a5fd
pillow@6.2.2
10.3.0

Open the chart page →

1,236
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pillow@8.3.1
10.3.0

Open the chart page →

24,293
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
pillow@7.2.0
10.3.0

Open the chart page →

7,984
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
pillow@10.1.0
10.3.0

Open the chart page →

16,384
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
10.3.0

Open the chart page →

6,501
frigateimprowisedVerified publisher1.1.01 of 1See more

frigate improwised 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
pillow@10.2.0
10.3.0

Open the chart page →

2,159
twitch-channel-points-minerjacobcolvinVerified publisher0.1.01 of 1See more

twitch-channel-points-miner jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
pillow@10.0.0
10.3.0

Open the chart page →

1,088
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
pillow@9.4.0
10.3.0

Open the chart page →

10,780
frigatek8s-home-lab-repo9.1.11 of 1See more

frigate k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@8.1.2
10.3.0

Open the chart page →

2,370
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
pillow@10.0.1
10.3.0

Open the chart page →

6,447
exposureloglsst-sqre0.2.11 of 1See more

exposurelog lsst-sqre 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
lsstsqre/exposurelog:0.8.079b00fb67a65
pillow@9.0.1
10.3.0

Open the chart page →

2,078
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pillow@10.2.0
10.3.0

Open the chart page →

4,647
mlflowmondata-helm-chartsVerified publisher0.2.31 of 1See more

mlflow mondata-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pillow@9.5.0
10.3.0

Open the chart page →

3,811
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pillow@8.4.0
10.3.0

Open the chart page →

8,556
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
pillow@9.4.0
10.3.0

Open the chart page →

5,456
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
10.3.0

Open the chart page →

55,726
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
pillow@5.4.1
10.3.0

Open the chart page →

27,633
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
pillow@9.2.0
10.3.0

Open the chart page →

22,084
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
pillow@9.4.0
10.3.0

Open the chart page →

7,685
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
pillow@10.2.0
10.3.0

Open the chart page →

7,431
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
pillow@5.4.1
pillow@5.4.1-2+deb10u1
10.3.0
5.4.1-2+deb10u6

Open the chart page →

8,694
frigatesmarthallVerified publisher1.0.61 of 1See more

frigate smarthall 1.0.6

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pillow@8.1.2
10.3.0

Open the chart page →

2,243
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pillow@8.4.0
10.3.0

Open the chart page →

8,715
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
pillow@10.2.0
10.3.0

Open the chart page →

4,393
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
pillow@10.2.0
10.3.0

Open the chart page →

39,090
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
opea/llm-docsum-tgi:1.002f9e8fa5d71
pillow@10.2.0
10.3.0

Open the chart page →

28,858
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
pillow@10.2.0
10.3.0

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
pillow@10.2.0
10.3.0

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
pillow@10.2.0
10.3.0

Open the chart page →

4,377
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
pillow@9.4.0
10.3.0

Open the chart page →

3,164
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-28219.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pillow@10.2.0
10.3.0

Open the chart page →

7,085

Container images carrying it

91 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pillow@4.3.0
10.3.0
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
10.3.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
pillow@9.2.0
10.3.0
1
nlmacamp/check_mk:latest5dbb8589f824
pillow@5.0.0
10.3.0
1
opea/asr:1.025dd26d9cd09
pillow@10.2.0
10.3.0
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
pillow@10.2.0
10.3.0
1
opea/speecht5:1.0249afad3d268
pillow@10.2.0
10.3.0
1
opea/tts:1.0257ae94709e9
pillow@10.2.0
10.3.0
1
opendatacube/explorer:latest120457ffcd69
pillow@10.2.0
10.3.0
1
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
pillow@5.1.0
5.1.0-1ubuntu0.8+esm1
10.3.0
1
opendatacube/wps:latest80df355a660b
pillow@9.0.1
10.3.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
pillow@10.2.0
10.3.0
1
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
pillow@10.0.0
10.3.0
1
robmarkcole/deepstack-ui:latest410275726459
pillow@8.3.2
10.3.0
1
scrapinghub/splash:3.4.1a5f89bc84606
pillow@5.4.1
10.3.0
1
seafileltd/seafile-mc:9.0.106693911bcc40
pillow@9.3.0
10.3.0
1
seafileltd/seafile-mc:10.0.170628f29c663
pillow@9.3.0
10.3.0
1
seafileltd/seafile-mc:9.0.97ac833196f60
pillow@9.2.0
10.3.0
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
pillow@10.2.0
10.3.0
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pillow@8.3.1
10.3.0
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pillow@9.4.0
10.3.0
1
taigaio/taiga-back:6.4.29f97323cc150
pillow@8.2.0
10.3.0
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pillow@5.0.0
10.3.0
1
timothyclarke/wptserver:2018-03-0840a80ced8031
pillow@2.6.1
10.3.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
pillow@9.0.0
10.3.0
1
weblate/weblate:3.11.3-182848df56ecd
pillow@5.4.1
pillow@5.4.1-2+deb10u1
10.3.0
5.4.1-2+deb10u6
1
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pillow@8.4.0
10.3.0
1
zurdi15/romm:2.3.12db88fe44c89
pillow@10.1.0
10.3.0
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
pillow@10.2.0
10.3.0
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pillow@8.1.2
10.3.0
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
pillow@10.2.0
10.3.0
1
ghcr.io/dask/dask:2024.1.0080150de7d86
pillow@10.0.1
10.3.0
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
pillow@10.2.0
10.3.0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pillow@9.1.0
10.3.0
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pillow@10.1.0
10.3.0
1
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
pillow@6.2.2
10.3.0
1
ghcr.io/linuxserver/pyload:version-5de90278d3c87933a5fd
pillow@6.2.2
10.3.0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pillow@10.2.0
10.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
pillow@9.2.0
10.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
pillow@10.1.0
10.3.0
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pillow@9.4.0
pillow@9.4.0-1.1+b1
10.3.0
9.4.0-1.1+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.