StackRadar

CVE-2026-42308

Medium

Advisory

Published 4 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
181
of 17,781 indexed, latest versions
Container images
184
deployed by those charts
Fix available
2 of 2
affected packages

Pillow has an integer overflow when processing fonts

Carried by container images the latest versions of 181 of 17,781 indexed charts deploy, on 184 images.

Affected packageAffected versionsFixed inImages
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+33 more12.2.0184
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.0.1-1ubuntu0.3+3 more9.0.1-1ubuntu0.4, 10.2.0-1ubuntu1.210
OSV records
DEBIAN-CVE-2026-42308GHSA-wjx4-4jcj-g98jUBUNTU-CVE-2026-42308
Also known as
BIT-pillow-2026-42308, PYSEC-2026-165, USN-8399-1

Charts affected

181 by stars
ChartLatestAffected imagesRadar Score
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pillow@9.3.0
12.2.0

Open the chart page →

4,085
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pillow@10.4.0
12.2.0

Open the chart page →

2,183
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
pillow@9.0.1
12.2.0

Open the chart page →

1,489
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
12.2.0

Open the chart page →

1,150
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
pillow@5.1.0
no fix listed
12.2.0

Open the chart page →

13,551
mylargeek-cookbookVerified publisher4.4.21 of 1See more

mylar geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
pillow@6.2.2
12.2.0

Open the chart page →

1,423
pyloadgeek-cookbookVerified publisher6.4.21 of 1See more

pyload geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/pyload:version-5de90278d3c87933a5fd
pillow@6.2.2
12.2.0

Open the chart page →

1,236
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pillow@8.3.1
12.2.0

Open the chart page →

24,293
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pillow@12.0.0
12.2.0

Open the chart page →

8,923
esphomehelm-chart-roeiVerified publisher2025.3.01 of 1See more

esphome helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
esphome/esphome:2025.3.0def8b6e4f517
pillow@10.4.0
12.2.0

Open the chart page →

6,008
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
pillow@11.1.0
12.2.0

Open the chart page →

4,647
supersethelm-charts-nr1.1.31 of 1See more

superset helm-charts-nr 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pillow@11.3.0
12.2.0

Open the chart page →

2,305
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
pillow@7.2.0
12.2.0

Open the chart page →

7,984
supersethelmforgeVerified publisher1.3.61 of 5See more

superset helmforge 1.3.6

1 of the 5 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
apache/superset:6.1.016b50bbef664
pillow@11.3.0
12.2.0

Open the chart page →

5,714
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
pillow@11.1.0
12.2.0

Open the chart page →

25,017
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
pillow@10.1.0
12.2.0

Open the chart page →

16,384
ilum-streamlitilumVerified publisher0.1.01 of 1See more

ilum-streamlit ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pillow@12.0.0
12.2.0

Open the chart page →

2,736
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
12.2.0

Open the chart page →

6,501
frigateimprowisedVerified publisher1.1.01 of 1See more

frigate improwised 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
pillow@10.2.0
12.2.0

Open the chart page →

2,159
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
pillow@11.1.0
12.2.0

Open the chart page →

5,062
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
pillow@12.1.1
12.2.0

Open the chart page →

3,157
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
pillow@11.0.0
12.2.0

Open the chart page →

17,852
inventreeinventreeOfficialVerified publisher0.4.281 of 2See more

inventree inventree 0.4.28

1 of the 2 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
pillow@11.1.0
12.2.0

Open the chart page →

5,788
twitch-channel-points-minerjacobcolvinVerified publisher0.1.01 of 1See more

twitch-channel-points-miner jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
pillow@10.0.0
12.2.0

Open the chart page →

1,088
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
pillow@9.4.0-1.1+deb12u1
pillow@9.4.0
no fix listed
12.2.0

Open the chart page →

10,780
beetsk8s-home-lab-repo3.1.11 of 1See more

beets k8s-home-lab-repo 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
pillow@11.2.1
12.2.0

Open the chart page →

2,733
frigatek8s-home-lab-repo9.1.11 of 1See more

frigate k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@8.1.2
12.2.0

Open the chart page →

2,370
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pillow@11.3.0
12.2.0

Open the chart page →

9,103
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pillow@12.1.1
12.2.0

Open the chart page →

7,081
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
pillow@10.0.1
12.2.0

Open the chart page →

6,447
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pillow@10.4.0
12.2.0

Open the chart page →

8,405
delugelinkding0.2.31 of 1See more

deluge linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pillow@11.2.1
12.2.0

Open the chart page →

1,433
calendar-apiliturgical0.1.51 of 1See more

calendar-api liturgical 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
pillow@11.3.0
12.2.0

Open the chart page →

1,556
liturgical-apiliturgical0.2.111 of 1See more

liturgical-api liturgical 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
pillow@12.1.1
12.2.0

Open the chart page →

1,004
exposureloglsst-sqre0.2.11 of 1See more

exposurelog lsst-sqre 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
lsstsqre/exposurelog:0.8.079b00fb67a65
pillow@9.0.1
12.2.0

Open the chart page →

2,078
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pillow@10.2.0
12.2.0

Open the chart page →

4,647
meerschaummeerschaumVerified publisher0.2.01 of 1See more

meerschaum meerschaum 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
bmeares/meerschaum:2.8.48e9c5bacaa82
pillow@11.1.0
12.2.0

Open the chart page →

5,823
mlflowmondata-helm-chartsVerified publisher0.2.31 of 1See more

mlflow mondata-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pillow@9.5.0
12.2.0

Open the chart page →

3,811
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pillow@8.4.0
12.2.0

Open the chart page →

8,556
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
pillow@11.3.0
12.2.0

Open the chart page →

11,950
szurubooru-servermy0nVerified publisher0.2.51 of 3See more

szurubooru-server my0n 0.2.5

1 of the 3 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
szurubooru/server:2.5accf2ad9fbc3
pillow@11.2.1
12.2.0

Open the chart page →

1,043
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
pillow@9.4.0
12.2.0

Open the chart page →

5,456
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
12.2.0

Open the chart page →

55,726
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
pillow@11.1.0
12.2.0

Open the chart page →

7,310
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
pillow@5.4.1
12.2.0

Open the chart page →

27,633
chatbot-ai-sampleopenshift0.1.61 of 4See more

chatbot-ai-sample openshift 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
pillow@10.3.0
12.2.0

Open the chart page →

18,922
ctfdpascaliskeVerified publisher2.0.01 of 1See more

ctfd pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
pillow@11.3.0
12.2.0

Open the chart page →

2,376
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
pillow@12.0.0
12.2.0

Open the chart page →

4,749
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
pillow@9.2.0
12.2.0

Open the chart page →

22,084
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2026-42308.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
pillow@11.3.0
12.2.0

Open the chart page →

4,616

Container images carrying it

184 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.2.0
4
apache/superset:6.1.0:latest16b50bbef664
pillow@11.3.0
12.2.0
3
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
12.2.0
3
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@8.1.2
12.2.0
2
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.2.0
2
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.2.0
2
opea/retriever-redis:1.0eb746b263705
pillow@10.2.0
12.2.0
2
opendatacube/ows:latest668cbb41473c
pillow@10.2.0-1ubuntu1
pillow@10.2.0
10.2.0-1ubuntu1.2
12.2.0
2
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.2.0
2
weblate/weblate:4.2.2-169c160d37a3c
pillow@7.2.0
12.2.0
2
allegroai/clearml:2.0.0-613713ae38f7daf
pillow@11.0.0
12.2.0
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
pillow@9.4.0
12.2.0
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
pillow@9.4.0
12.2.0
1
anujdatar/cups:25.07.01685df04a643b
pillow@9.4.0-1.1+deb12u1
pillow@9.4.0
no fix listed
12.2.0
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
pillow@9.1.0
12.2.0
1
apache/superset:4.0.1ab9467fd712c
pillow@10.2.0
12.2.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pillow@10.4.0
12.2.0
1
apsl/thumbor:6.7.051e2de5c2c70
pillow@5.4.1
12.2.0
1
aristidetm/basic-notebook:3.6.5469dbc951224
pillow@10.4.0
12.2.0
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
pillow@10.2.0
12.2.0
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pillow@10.3.0
12.2.0
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pillow@9.5.0
12.2.0
1
baserow/backend:1.31.1e0b3c8130b91
pillow@10.3.0
12.2.0
1
baserow/baserow:1.30.1df0c42eb67e8
pillow@10.3.0
12.2.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pillow@12.0.0
12.2.0
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
pillow@7.0.0-4ubuntu0.5
pillow@8.1.0
no fix listed
12.2.0
1
bmeares/meerschaum:2.8.48e9c5bacaa82
pillow@11.1.0
12.2.0
1
bnjbvr/kresus:0.22.137e216b182c8
pillow@11.0.0
12.2.0
1
buntha/mlflow:2.1.1154542cc3083
pillow@9.3.0
12.2.0
1
camerahub/camerahub:0.36.23a5af37dd6e1b
pillow@9.5.0
12.2.0
1
copyparty/ac:1.19.200a0a8605062c
pillow@11.2.1
12.2.0
1
daskdev/dask:1.1.04ecd7bc35500
pillow@5.3.0
12.2.0
1
daskdev/dask-notebook:1.1.0052630f5ca04
pillow@5.4.1
12.2.0
1
datamate/seafile-professional:11.0.202dd66b722464
pillow@10.2.0
12.2.0
1
deconzcommunity/deconz:2.29.2062de2362641
pillow@9.4.0-1.1+deb12u1
pillow@9.4.0
no fix listed
12.2.0
1
deconzcommunity/deconz:2.12.066541bbb78952
pillow@5.4.1
12.2.0
1
dpage/pgadmin4:7.537946e4f3e7b
pillow@9.5.0
12.2.0
1
dpage/pgadmin4:9.11.050700ac17936
pillow@12.0.0
12.2.0
1
dpage/pgadmin4:9.252cb72a9e3da
pillow@11.1.0
12.2.0
1
dpage/pgadmin4:8.13561c1f8f99f2
pillow@11.0.0
12.2.0
1
esphome/esphome:1.18.03f51ec10e823
pillow@5.4.1
12.2.0
1
esphome/esphome:2024.3.09ab8cc88b28c
pillow@10.2.0
12.2.0
1
esphome/esphome:2024.12.2b2c6322700ac
pillow@10.4.0
12.2.0
1
esphome/esphome:2025.3.0def8b6e4f517
pillow@10.4.0
12.2.0
1
evk02/mlflow:2.2.1ef6ff257ef35
pillow@9.4.0
12.2.0
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pillow@9.3.0
12.2.0
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pillow@11.2.1
12.2.0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
pillow@7.2.0
12.2.0
1
heartexlabs/label-studio:latestaa461572e8f9
pillow@12.1.1
12.2.0
1
hhyo/archery:v1.9.11aa41843419e
pillow@9.0.1
12.2.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.