StackRadar

CVE-2026-42310

Medium

Advisory

Published 4 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
180
of 17,781 indexed, latest versions
Container images
183
deployed by those charts
Fix available
2 of 2
affected packages

Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

Carried by container images the latest versions of 180 of 17,781 indexed charts deploy, on 183 images.

Affected packageAffected versionsFixed inImages
pillowpypi4.3.0, 5.0.0, 5.1.0, 5.2.0+32 more12.2.0183
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.0.1-1ubuntu0.3+3 more9.0.1-1ubuntu0.4, 10.2.0-1ubuntu1.210
OSV records
DEBIAN-CVE-2026-42310GHSA-r73j-pqj5-w3x7UBUNTU-CVE-2026-42310
Also known as
BIT-pillow-2026-42310, PYSEC-2026-2874, USN-8399-1

Charts affected

180 by stars
ChartLatestAffected imagesRadar Score
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
pillow@10.2.0
12.2.0

Open the chart page →

7,431
rhbk-neurofacerhbk-neurofaceVerified publisher1.0.01 of 4See more

rhbk-neuroface rhbk-neuroface 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
pillow@11.1.0
12.2.0

Open the chart page →

3,781
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
pillow@11.0.0
12.2.0

Open the chart page →

15,591
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
pillow@11.1.0
12.2.0

Open the chart page →

9,256
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pillow@11.3.0
12.2.0

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
pillow@11.3.0
12.2.0

Open the chart page →

4,499
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
pillow@11.0.0
12.2.0

Open the chart page →

1,713
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
pillow@11.1.0
12.2.0

Open the chart page →

2,817
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pillow@12.1.1
12.2.0

Open the chart page →

5,201
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
pillow@5.4.1
12.2.0

Open the chart page →

8,694
frigatesmarthallVerified publisher1.0.61 of 1See more

frigate smarthall 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pillow@8.1.2
12.2.0

Open the chart page →

2,243
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
pillow@10.3.0
12.2.0

Open the chart page →

5,565
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pillow@8.4.0
12.2.0

Open the chart page →

8,715
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
pillow@10.2.0
12.2.0

Open the chart page →

4,393
chatqnatest-opea1.0.05 of 11See more

chatqna test-opea 1.0.0

5 of the 11 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
pillow@10.4.0
12.2.0
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.2.0
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.2.0
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.2.0
opea/retriever-redis:1.0eb746b263705
pillow@10.2.0
12.2.0

Open the chart page →

39,090
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
pillow@10.4.0
12.2.0
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.2.0

Open the chart page →

28,814
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
pillow@10.4.0
12.2.0
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.2.0

Open the chart page →

28,385
docsumtest-opea1.0.02 of 5See more

docsum test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
pillow@10.4.0
12.2.0
opea/llm-docsum-tgi:1.002f9e8fa5d71
pillow@10.2.0
12.2.0

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.2.0

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
pillow@10.4.0
12.2.0

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.2.0

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.2.0

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
pillow@10.2.0
12.2.0

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
pillow@10.2.0
12.2.0

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
pillow@10.2.0
12.2.0

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
pillow@10.4.0
12.2.0

Open the chart page →

5,350
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
pillow@9.4.0
12.2.0

Open the chart page →

3,164
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pillow@11.1.0
12.2.0

Open the chart page →

4,768
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
pillow@11.3.0
12.2.0

Open the chart page →

7,628
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42310.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pillow@10.2.0
12.2.0

Open the chart page →

7,085

Container images carrying it

183 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pillow@9.1.0
12.2.0
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pillow@10.1.0
12.2.0
1
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
pillow@11.2.1
12.2.0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
pillow@12.1.1
12.2.0
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pillow@12.1.1
12.2.0
1
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
pillow@10.4.0
12.2.0
1
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
pillow@6.2.2
12.2.0
1
ghcr.io/linuxserver/pyload:version-5de90278d3c87933a5fd
pillow@6.2.2
12.2.0
1
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
pillow@11.3.0
12.2.0
1
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
pillow@12.1.1
12.2.0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pillow@10.2.0
12.2.0
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pillow@11.3.0
12.2.0
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
pillow@10.3.0
12.2.0
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pillow@12.0.0
12.2.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pillow@10.3.0
12.2.0
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
pillow@11.3.0
12.2.0
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pillow@12.1.1
12.2.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
pillow@10.4.0
12.2.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
pillow@11.3.0
12.2.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pillow@11.3.0
12.2.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
pillow@11.3.0
12.2.0
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
pillow@9.2.0
12.2.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
pillow@10.1.0
12.2.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pillow@11.3.0
12.2.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pillow@10.4.0
12.2.0
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
pillow@11.2.1
12.2.0
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pillow@9.4.0-1.1+b1
pillow@9.4.0
no fix listed
12.2.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
pillow@10.3.0
12.2.0
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
pillow@11.1.0
12.2.0
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
pillow@11.1.0
12.2.0
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
pillow@12.0.0
12.2.0
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pillow@12.0.0
12.2.0
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
pillow@10.3.0
12.2.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.