StackRadar

CVE-2026-42311

High

Advisory

Published 4 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.6
base score, highest
EPSS
0.002
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
93
of 17,781 indexed, latest versions
Container images
93
deployed by those charts
Fix available
1 of 1
affected package

Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)

Carried by container images the latest versions of 93 of 17,781 indexed charts deploy, on 93 images.

Affected packageAffected versionsFixed inImages
pillowpypi10.3.0, 10.4.0, 11.0.0, 11.1.0+5 more12.2.093
OSV records
GHSA-pwv6-vv43-88gr
Also known as
BIT-pillow-2026-42311, PYSEC-2026-2252

Charts affected

93 by stars
ChartLatestAffected imagesRadar Score
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
pillow@11.0.0
12.2.0

Open the chart page →

10,622
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
pillow@10.4.0
12.2.0

Open the chart page →

6,543
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
pillow@10.4.0
12.2.0

Open the chart page →

3,004
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
openmined/syft-backend:0.9.5b72f74a68b32
pillow@11.1.0
12.2.0

Open the chart page →

17,245
netboxstartechnicaVerified publisher5.1.01 of 4See more

netbox startechnica 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
pillow@10.3.0
12.2.0

Open the chart page →

1,650
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
pillow@10.3.0
12.2.0

Open the chart page →

17,404
mlflowgetindataVerified publisher0.1.21 of 1See more

mlflow getindata 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
gcr.io/getindata-images-public/mlflow:latest25d6975951f1
pillow@10.3.0
12.2.0

Open the chart page →

2,452
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
pillow@12.1.1
12.2.0

Open the chart page →

4,634
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
pillow@12.0.0
12.2.0

Open the chart page →

107,811
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pillow@12.0.0
12.2.0

Open the chart page →

3,804
paperless-ngxalexmorbo-paperless-ngxVerified publisher0.2.01 of 2See more

paperless-ngx alexmorbo-paperless-ngx 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
pillow@11.3.0
12.2.0

Open the chart page →

12,037
psonoankra-chartsVerified publisher1.2.01 of 2See more

psono ankra-charts 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
psono/psono-server:5.0.03b974b43ea03
pillow@10.3.0
12.2.0

Open the chart page →

2,388
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
pillow@10.3.0
12.2.0

Open the chart page →

9,971
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
pillow@10.4.0
12.2.0

Open the chart page →

13,761
copypartyernail-copyparty2.0.01 of 1See more

copyparty ernail-copyparty 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
copyparty/ac:1.19.200a0a8605062c
pillow@11.2.1
12.2.0

Open the chart page →

1,685
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.2.0

Open the chart page →

8,496
obicogabe565Verified publisher0.6.01 of 3See more

obico gabe565 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
pillow@11.1.0
12.2.0

Open the chart page →

1,965
hasher-matcher-actionerhasher-matcher-actioner1.0.01 of 1See more

hasher-matcher-actioner hasher-matcher-actioner 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/facebook/threatexchange/hma:1.0.1784d09c6b75a7
pillow@11.2.1
12.2.0

Open the chart page →

910
helmuphelmupVerified publisher0.1.02 of 3See more

helmup helmup 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
pillow@10.4.0
12.2.0
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
pillow@10.3.0
12.2.0

Open the chart page →

16,514
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
pillow@10.4.0
12.2.0

Open the chart page →

15,712
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
pillow@11.3.0
12.2.0

Open the chart page →

11,764
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
pillow@10.3.0
12.2.0

Open the chart page →

20,403
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
pillow@11.0.0
12.2.0

Open the chart page →

4,292
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
pillow@11.3.0
12.2.0

Open the chart page →

7,201
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
pillow@11.2.1
12.2.0

Open the chart page →

6,873
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pillow@11.3.0
12.2.0

Open the chart page →

3,929
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
pillow@11.0.0
12.2.0

Open the chart page →

2,928
streamlit-appstreamlit-appVerified publisher0.2.01 of 1See more

streamlit-app streamlit-app 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
sruthitanneru/pi-sample:ui-lateste565ea454ffd
pillow@11.0.0
12.2.0

Open the chart page →

1,696
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.2.0

Open the chart page →

9,148
verbacapverbacapVerified publisher1.0.71 of 1See more

verbacap verbacap 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pillow@10.3.0
12.2.0

Open the chart page →

2,233
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
pillow@10.4.0
12.2.0

Open the chart page →

6,324
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
pillow@12.1.1
12.2.0

Open the chart page →

7,239
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pillow@12.1.1
12.2.0

Open the chart page →

5,558
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
pillow@12.0.0
12.2.0

Open the chart page →

1,565
smartorchestratorassist-iot-smart-orchestrator4.0.01 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

1 of the 14 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pillow@10.3.0
12.2.0

Open the chart page →

45,363
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
pillow@10.3.0
12.2.0

Open the chart page →

10,145
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pillow@11.1.0
12.2.0

Open the chart page →

20,900
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pillow@11.2.1
12.2.0

Open the chart page →

6,162
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pillow@11.2.1
12.2.0
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.2.0
opencsghq/label-studio:v2.4.0b4e849fcf94a
pillow@11.3.0
12.2.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pillow@11.3.0
12.2.0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
pillow@11.3.0
12.2.0

Open the chart page →

6,632
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
pillow@10.4.0
12.2.0

Open the chart page →

16,604
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pillow@11.3.0
12.2.0

Open the chart page →

2,305
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pillow@12.0.0
12.2.0

Open the chart page →

11,160
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
pillow@11.1.0
12.2.0

Open the chart page →

19,224
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
pillow@10.4.0
12.2.0

Open the chart page →

2,896
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pillow@10.4.0
12.2.0

Open the chart page →

2,183
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pillow@12.0.0
12.2.0

Open the chart page →

8,923
esphomehelm-chart-roeiVerified publisher2025.3.01 of 1See more

esphome helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
esphome/esphome:2025.3.0def8b6e4f517
pillow@10.4.0
12.2.0

Open the chart page →

6,008
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-42311.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
pillow@11.1.0
12.2.0

Open the chart page →

4,647

Container images carrying it

93 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.2.0
4
apache/superset:6.1.0:latest16b50bbef664
pillow@11.3.0
12.2.0
3
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.2.0
2
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.2.0
2
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.2.0
2
allegroai/clearml:2.0.0-613713ae38f7daf
pillow@11.0.0
12.2.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pillow@10.4.0
12.2.0
1
aristidetm/basic-notebook:3.6.5469dbc951224
pillow@10.4.0
12.2.0
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pillow@10.3.0
12.2.0
1
baserow/backend:1.31.1e0b3c8130b91
pillow@10.3.0
12.2.0
1
baserow/baserow:1.30.1df0c42eb67e8
pillow@10.3.0
12.2.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pillow@12.0.0
12.2.0
1
bmeares/meerschaum:2.8.48e9c5bacaa82
pillow@11.1.0
12.2.0
1
bnjbvr/kresus:0.22.137e216b182c8
pillow@11.0.0
12.2.0
1
copyparty/ac:1.19.200a0a8605062c
pillow@11.2.1
12.2.0
1
dpage/pgadmin4:9.11.050700ac17936
pillow@12.0.0
12.2.0
1
dpage/pgadmin4:9.252cb72a9e3da
pillow@11.1.0
12.2.0
1
dpage/pgadmin4:8.13561c1f8f99f2
pillow@11.0.0
12.2.0
1
esphome/esphome:2024.12.2b2c6322700ac
pillow@10.4.0
12.2.0
1
esphome/esphome:2025.3.0def8b6e4f517
pillow@10.4.0
12.2.0
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pillow@11.2.1
12.2.0
1
heartexlabs/label-studio:latestaa461572e8f9
pillow@12.1.1
12.2.0
1
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pillow@12.0.0
12.2.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
pillow@11.0.0
12.2.0
1
inventree/inventree:1.5.4a946ec09da3e
pillow@11.1.0
12.2.0
1
langgenius/dify-api:1.0.0066035f93856
pillow@11.1.0
12.2.0
1
langgenius/dify-api:0.6.11fca918260dd6
pillow@10.3.0
12.2.0
1
linuxserver/calibre-web:0.6.24241009026e6f
pillow@11.3.0
12.2.0
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pillow@11.2.1
12.2.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pillow@12.1.1
12.2.0
1
mathesar/mathesar:0.12.0091757cb01fe
pillow@12.1.1
12.2.0
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
pillow@11.1.0
12.2.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
pillow@10.3.0
12.2.0
1
opea/chatqna:1.038c51b791efa
pillow@10.4.0
12.2.0
1
opea/codegen:1.058f91683892d
pillow@10.4.0
12.2.0
1
opea/codetrans:1.0e2436483b73d
pillow@10.4.0
12.2.0
1
opea/docsum:1.03eaa91849512
pillow@10.4.0
12.2.0
1
opea/guardrails-tgi:1.0262c6048aab8
pillow@10.4.0
12.2.0
1
opea/guardrails-tgi:latestf68bec6a1271
pillow@11.1.0
12.2.0
1
opea/web-retriever-chroma:1.0fe08165d7770
pillow@10.4.0
12.2.0
1
openbas/caldera-server:5.1.0a277796d9724
pillow@11.1.0
12.2.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pillow@11.2.1
12.2.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.2.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pillow@11.3.0
12.2.0
1
opencsghq/label-studio:v2.5.047e22aa71870
pillow@11.3.0
12.2.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
pillow@11.3.0
12.2.0
1
openmined/syft-backend:0.9.5b72f74a68b32
pillow@11.1.0
12.2.0
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
pillow@11.3.0
12.2.0
1
psono/psono-server:5.0.03b974b43ea03
pillow@10.3.0
12.2.0
1
rommapp/romm:4.4.1b909e95d1aab
pillow@10.4.0
12.2.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.