StackRadar

CVE-2026-25990

High

Advisory

Published 11 Feb 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.6
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
86
of 17,781 indexed, latest versions
Container images
86
deployed by those charts
Fix available
1 of 1
affected package

Pillow affected by out-of-bounds write when loading PSD images

Carried by container images the latest versions of 86 of 17,781 indexed charts deploy, on 86 images.

Affected packageAffected versionsFixed inImages
pillowpypi10.3.0, 10.4.0, 11.0.0, 11.1.0+4 more12.1.186
OSV records
GHSA-cfh3-3jmp-rvhc
Also known as
BIT-pillow-2026-25990, PYSEC-2026-2249

Charts affected

86 by stars
ChartLatestAffected imagesRadar Score
ilum-streamlitilumVerified publisher0.1.01 of 1See more

ilum-streamlit ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pillow@12.0.0
12.1.1

Open the chart page →

2,736
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
pillow@11.1.0
12.1.1

Open the chart page →

5,062
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
pillow@11.0.0
12.1.1

Open the chart page →

17,852
inventreeinventreeOfficialVerified publisher0.4.281 of 2See more

inventree inventree 0.4.28

1 of the 2 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
pillow@11.1.0
12.1.1

Open the chart page →

5,788
beetsk8s-home-lab-repo3.1.11 of 1See more

beets k8s-home-lab-repo 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
pillow@11.2.1
12.1.1

Open the chart page →

2,733
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pillow@11.3.0
12.1.1

Open the chart page →

9,103
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pillow@10.4.0
12.1.1

Open the chart page →

8,405
delugelinkding0.2.31 of 1See more

deluge linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pillow@11.2.1
12.1.1

Open the chart page →

1,433
calendar-apiliturgical0.1.51 of 1See more

calendar-api liturgical 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
pillow@11.3.0
12.1.1

Open the chart page →

1,556
meerschaummeerschaumVerified publisher0.2.01 of 1See more

meerschaum meerschaum 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
bmeares/meerschaum:2.8.48e9c5bacaa82
pillow@11.1.0
12.1.1

Open the chart page →

5,823
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
pillow@11.3.0
12.1.1

Open the chart page →

11,950
szurubooru-servermy0nVerified publisher0.2.51 of 3See more

szurubooru-server my0n 0.2.5

1 of the 3 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
szurubooru/server:2.5accf2ad9fbc3
pillow@11.2.1
12.1.1

Open the chart page →

1,043
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
pillow@11.1.0
12.1.1

Open the chart page →

7,310
chatbot-ai-sampleopenshift0.1.61 of 4See more

chatbot-ai-sample openshift 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
pillow@10.3.0
12.1.1

Open the chart page →

18,922
ctfdpascaliskeVerified publisher2.0.01 of 1See more

ctfd pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
pillow@11.3.0
12.1.1

Open the chart page →

2,376
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
pillow@12.0.0
12.1.1

Open the chart page →

4,749
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
pillow@11.3.0
12.1.1

Open the chart page →

4,616
rhbk-neurofacerhbk-neurofaceVerified publisher1.0.01 of 4See more

rhbk-neuroface rhbk-neuroface 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
pillow@11.1.0
12.1.1

Open the chart page →

3,781
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
pillow@11.0.0
12.1.1

Open the chart page →

15,591
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
pillow@11.1.0
12.1.1

Open the chart page →

9,256
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pillow@11.3.0
12.1.1

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
pillow@11.3.0
12.1.1

Open the chart page →

4,499
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
pillow@11.0.0
12.1.1

Open the chart page →

1,713
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
pillow@11.1.0
12.1.1

Open the chart page →

2,817
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
pillow@10.3.0
12.1.1

Open the chart page →

5,565
chatqnatest-opea1.0.04 of 11See more

chatqna test-opea 1.0.0

4 of the 11 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
pillow@10.4.0
12.1.1
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.1.1
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.1.1
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.1.1

Open the chart page →

39,090
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
pillow@10.4.0
12.1.1
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.1.1

Open the chart page →

28,814
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
pillow@10.4.0
12.1.1
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.1.1

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
pillow@10.4.0
12.1.1

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.1.1

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
pillow@10.4.0
12.1.1

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.1.1

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.1.1

Open the chart page →

4,985
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
pillow@10.4.0
12.1.1

Open the chart page →

5,350
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pillow@11.1.0
12.1.1

Open the chart page →

4,768
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-25990.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
pillow@11.3.0
12.1.1

Open the chart page →

7,628

Container images carrying it

86 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.1.1
4
apache/superset:6.1.0:latest16b50bbef664
pillow@11.3.0
12.1.1
3
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.1.1
2
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.1.1
2
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.1.1
2
allegroai/clearml:2.0.0-613713ae38f7daf
pillow@11.0.0
12.1.1
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pillow@10.4.0
12.1.1
1
aristidetm/basic-notebook:3.6.5469dbc951224
pillow@10.4.0
12.1.1
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pillow@10.3.0
12.1.1
1
baserow/backend:1.31.1e0b3c8130b91
pillow@10.3.0
12.1.1
1
baserow/baserow:1.30.1df0c42eb67e8
pillow@10.3.0
12.1.1
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pillow@12.0.0
12.1.1
1
bmeares/meerschaum:2.8.48e9c5bacaa82
pillow@11.1.0
12.1.1
1
bnjbvr/kresus:0.22.137e216b182c8
pillow@11.0.0
12.1.1
1
copyparty/ac:1.19.200a0a8605062c
pillow@11.2.1
12.1.1
1
dpage/pgadmin4:9.11.050700ac17936
pillow@12.0.0
12.1.1
1
dpage/pgadmin4:9.252cb72a9e3da
pillow@11.1.0
12.1.1
1
dpage/pgadmin4:8.13561c1f8f99f2
pillow@11.0.0
12.1.1
1
esphome/esphome:2024.12.2b2c6322700ac
pillow@10.4.0
12.1.1
1
esphome/esphome:2025.3.0def8b6e4f517
pillow@10.4.0
12.1.1
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pillow@11.2.1
12.1.1
1
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pillow@12.0.0
12.1.1
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
pillow@11.0.0
12.1.1
1
inventree/inventree:1.5.4a946ec09da3e
pillow@11.1.0
12.1.1
1
langgenius/dify-api:1.0.0066035f93856
pillow@11.1.0
12.1.1
1
langgenius/dify-api:0.6.11fca918260dd6
pillow@10.3.0
12.1.1
1
linuxserver/calibre-web:0.6.24241009026e6f
pillow@11.3.0
12.1.1
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pillow@11.2.1
12.1.1
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
pillow@11.1.0
12.1.1
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
pillow@10.3.0
12.1.1
1
opea/chatqna:1.038c51b791efa
pillow@10.4.0
12.1.1
1
opea/codegen:1.058f91683892d
pillow@10.4.0
12.1.1
1
opea/codetrans:1.0e2436483b73d
pillow@10.4.0
12.1.1
1
opea/docsum:1.03eaa91849512
pillow@10.4.0
12.1.1
1
opea/guardrails-tgi:1.0262c6048aab8
pillow@10.4.0
12.1.1
1
opea/guardrails-tgi:latestf68bec6a1271
pillow@11.1.0
12.1.1
1
opea/web-retriever-chroma:1.0fe08165d7770
pillow@10.4.0
12.1.1
1
openbas/caldera-server:5.1.0a277796d9724
pillow@11.1.0
12.1.1
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pillow@11.2.1
12.1.1
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.1.1
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pillow@11.3.0
12.1.1
1
opencsghq/label-studio:v2.5.047e22aa71870
pillow@11.3.0
12.1.1
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
pillow@11.3.0
12.1.1
1
openmined/syft-backend:0.9.5b72f74a68b32
pillow@11.1.0
12.1.1
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
pillow@11.3.0
12.1.1
1
psono/psono-server:5.0.03b974b43ea03
pillow@10.3.0
12.1.1
1
rommapp/romm:4.4.1b909e95d1aab
pillow@10.4.0
12.1.1
1
saidsef/scapy-containerised:v2025.02f17f7c435891
pillow@11.1.0
12.1.1
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
pillow@10.4.0
12.1.1
1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
pillow@10.3.0
12.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.