StackRadar

CVE-2026-59203

High

Advisory

Published 14 Jul 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
44
of 17,781 indexed, latest versions
Container images
41
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 44 of 17,781 indexed charts deploy, on 41 images.

Affected packageAffected versionsFixed inImages
pillowpypi12.0.0, 12.1.0, 12.1.1, 12.2.012.3.034
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.0.1-1ubuntu0.3+1 moreno fix listed7
OSV records
PYSEC-2026-3452UBUNTU-CVE-2026-59203
Also known as
BIT-pillow-2026-59203, GHSA-pg7v-jwj7-p798

Charts affected

44 by stars
ChartLatestAffected imagesRadar Score
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
pillow@12.2.0
12.3.0

Open the chart page →

4,332
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
pillow@7.0.0-4ubuntu0.5
no fix listed

Open the chart page →

10,598
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
pillow@12.1.1
12.3.0

Open the chart page →

4,634
oesopsmxVerified publisher4.0.321 of 25See more

oes opsmx 4.0.32

1 of the 25 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
pillow@12.0.0
12.3.0

Open the chart page →

107,811
mealieth-chartsVerified publisher0.5.11 of 1See more

mealie th-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pillow@12.0.0
12.3.0

Open the chart page →

3,804
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
wger/server:2.6997ead43aabd
pillow@12.2.0
12.3.0

Open the chart page →

8,491
aibrixdanchevVerified publisher0.7.01 of 5See more

aibrix danchev 0.7.0

1 of the 5 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
aibrix/metadata-service:v0.7.063fb81a64377
pillow@12.2.0
12.3.0

Open the chart page →

5,274
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
pillow@10.2.0-1ubuntu1
no fix listed

Open the chart page →

4,854
craftycontrollerdrewburr-labs-helm-chartsVerified publisher0.3.01 of 1See more

craftycontroller drewburr-labs-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
pillow@12.2.0
12.3.0

Open the chart page →

3,671
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.3.0

Open the chart page →

8,496
opentelemetry-demoopentelemetry-helmVerified publisher0.41.11 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

1 of the 34 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-chatbot66ba53497f1f
pillow@12.2.0
12.3.0

Open the chart page →

22,420
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
pillow@12.2.0
12.3.0

Open the chart page →

8,158
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0-1ubuntu0.6
no fix listed

Open the chart page →

13,541
sentry-k8ssentry-k8sVerified publisher1.4.11 of 11See more

sentry-k8s sentry-k8s 1.4.1

1 of the 11 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
pillow@12.2.0
12.3.0

Open the chart page →

16,449
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.3.0

Open the chart page →

9,148
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pillow@12.2.0
12.3.0

Open the chart page →

5,817
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
pillow@12.1.1
12.3.0

Open the chart page →

7,239
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pillow@12.1.1
12.3.0

Open the chart page →

5,558
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
pillow@12.0.0
12.3.0

Open the chart page →

1,565
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pillow@12.2.0
12.3.0

Open the chart page →

4,803
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pillow@12.2.0
12.3.0

Open the chart page →

4,601
csghubcsghubVerified publisher2.4.31 of 34See more

csghub csghub 2.4.3

1 of the 34 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.3.0

Open the chart page →

58,897
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
no fix listed

Open the chart page →

27,728
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0-1ubuntu1
no fix listed

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0-1ubuntu1
no fix listed

Open the chart page →

5,974
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
pillow@9.0.1-1ubuntu0.3
no fix listed

Open the chart page →

6,172
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pillow@12.0.0
12.3.0

Open the chart page →

11,160
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
no fix listed

Open the chart page →

13,551
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pillow@12.0.0
12.3.0

Open the chart page →

8,923
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
pillow@12.2.0
12.3.0

Open the chart page →

11,042
ilum-streamlitilumVerified publisher0.1.01 of 1See more

ilum-streamlit ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pillow@12.0.0
12.3.0

Open the chart page →

2,736
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
pillow@12.1.1
12.3.0

Open the chart page →

3,157
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
pillow@12.2.0
12.3.0

Open the chart page →

5,040
bazarrk8s-home-lab-repo11.3.21 of 1See more

bazarr k8s-home-lab-repo 11.3.2

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
pillow@12.2.0
12.3.0

Open the chart page →

1,794
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pillow@12.1.1
12.3.0

Open the chart page →

7,081
liturgical-apiliturgical0.2.111 of 1See more

liturgical-api liturgical 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
pillow@12.1.1
12.3.0

Open the chart page →

1,004
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
pillow@12.2.0
12.3.0

Open the chart page →

2,444
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
pillow@12.0.0
12.3.0

Open the chart page →

4,749
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pillow@12.2.0
12.3.0

Open the chart page →

7,436
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
pillow@12.2.0
12.3.0

Open the chart page →

6,207
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
pillow@12.2.0
12.3.0

Open the chart page →

1,577
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
pillow@12.2.0
12.3.0

Open the chart page →

19,560
search-proxysearch-proxy2026.38.01 of 1See more

search-proxy search-proxy 2026.38.0

1 of the 1 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
pillow@12.2.0
12.3.0

Open the chart page →

1,264
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-59203.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pillow@12.1.1
12.3.0

Open the chart page →

5,201

Container images carrying it

41 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opendatacube/ows:latest668cbb41473c
pillow@10.2.0-1ubuntu1
no fix listed
2
safeglobal/safe-config-service:latest09a5e495c219
pillow@12.2.0
12.3.0
2
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.3.0
2
aibrix/metadata-service:v0.7.063fb81a64377
pillow@12.2.0
12.3.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pillow@12.0.0
12.3.0
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
pillow@7.0.0-4ubuntu0.5
no fix listed
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
pillow@12.2.0
12.3.0
1
dpage/pgadmin4:9.11.050700ac17936
pillow@12.0.0
12.3.0
1
heartexlabs/label-studio:latestaa461572e8f9
pillow@12.1.1
12.3.0
1
homeassistant/home-assistant:2026.75a531753cea9
pillow@12.2.0
12.3.0
1
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pillow@12.0.0
12.3.0
1
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0-1ubuntu0.6
no fix listed
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
no fix listed
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pillow@12.1.1
12.3.0
1
mathesar/mathesar:0.12.0091757cb01fe
pillow@12.1.1
12.3.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
pillow@12.2.0
12.3.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.3.0
1
opendatacube/explorer:latest120457ffcd69
pillow@10.2.0-1ubuntu1
no fix listed
1
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
no fix listed
1
opendatacube/wps:latest80df355a660b
pillow@9.0.1-1ubuntu0.3
no fix listed
1
prowlercloud/prowler-api:5.31.14f252d579be2
pillow@12.2.0
12.3.0
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pillow@12.2.0
12.3.0
1
wger/server:2.6997ead43aabd
pillow@12.2.0
12.3.0
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
pillow@12.2.0
12.3.0
1
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
pillow@12.2.0
12.3.0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
pillow@12.0.0
12.3.0
1
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
pillow@12.2.0
12.3.0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
pillow@12.1.1
12.3.0
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pillow@12.1.1
12.3.0
1
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
pillow@12.2.0
12.3.0
1
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
pillow@12.1.1
12.3.0
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pillow@12.0.0
12.3.0
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pillow@12.2.0
12.3.0
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pillow@12.1.1
12.3.0
1
ghcr.io/open-telemetry/demo:3.0.0-chatbot66ba53497f1f
pillow@12.2.0
12.3.0
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
pillow@12.2.0
12.3.0
1
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
pillow@12.2.0
12.3.0
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pillow@12.2.0
12.3.0
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
pillow@12.0.0
12.3.0
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pillow@12.0.0
12.3.0
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
pillow@12.2.0
12.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.