StackRadar

CVE-2026-59204

High

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
179
of 17,781 indexed, latest versions
Container images
180
deployed by those charts
Fix available
1 of 2
affected packages

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

Carried by container images the latest versions of 179 of 17,781 indexed charts deploy, on 180 images.

Affected packageAffected versionsFixed inImages
pillowpypi8.2.0, 8.3.1, 8.3.2, 8.4.0+21 more12.3.0176
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.0.1-1ubuntu0.3+4 moreno fix listed11
OSV records
DEBIAN-CVE-2026-59204GHSA-vjc4-5qp5-m44jUBUNTU-CVE-2026-59204
Also known as
BIT-pillow-2026-59204, PYSEC-2026-3496

Charts affected

179 by stars
ChartLatestAffected imagesRadar Score
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
pillow@11.3.0
12.3.0

Open the chart page →

7,201
mlflow-controllermlflow-deployment-controller0.1.81 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pillow@9.4.0
12.3.0

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
pillow@9.3.0
12.3.0

Open the chart page →

5,804
opentelemetry-demoopentelemetry-helmVerified publisher0.41.11 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

1 of the 34 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-chatbot66ba53497f1f
pillow@12.2.0
12.3.0

Open the chart page →

22,420
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
pillow@11.2.1
12.3.0

Open the chart page →

6,873
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
pillow@12.2.0
12.3.0

Open the chart page →

8,158
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pillow@11.3.0
12.3.0

Open the chart page →

3,929
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0-1ubuntu0.6
no fix listed

Open the chart page →

13,541
sentry-k8ssentry-k8sVerified publisher1.4.11 of 11See more

sentry-k8s sentry-k8s 1.4.1

1 of the 11 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
pillow@12.2.0
12.3.0

Open the chart page →

16,449
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
pillow@11.0.0
12.3.0

Open the chart page →

2,928
streamlit-appstreamlit-appVerified publisher0.2.01 of 1See more

streamlit-app streamlit-app 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
sruthitanneru/pi-sample:ui-lateste565ea454ffd
pillow@11.0.0
12.3.0

Open the chart page →

1,696
synapsesudermanjr1.1.51 of 1See more

synapse sudermanjr 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pillow@9.0.1
12.3.0

Open the chart page →

3,332
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.3.0

Open the chart page →

9,148
verbacapverbacapVerified publisher1.0.71 of 1See more

verbacap verbacap 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pillow@10.3.0
12.3.0

Open the chart page →

2,233
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
pillow@10.4.0
12.3.0

Open the chart page →

6,324
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pillow@12.2.0
12.3.0

Open the chart page →

5,817
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
pillow@12.1.1
12.3.0

Open the chart page →

7,239
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pillow@12.1.1
12.3.0

Open the chart page →

5,558
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
pillow@12.0.0
12.3.0

Open the chart page →

1,565
pgadminarunalakmalVerified publisher0.1.01 of 1See more

pgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
12.3.0

Open the chart page →

2,418
swdpgadminarunalakmalVerified publisher0.1.01 of 1See more

swdpgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
12.3.0

Open the chart page →

2,418
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
12.3.0

Open the chart page →

10,061
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
pillow@10.2.0
12.3.0
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pillow@10.3.0
12.3.0
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pillow@9.5.0
12.3.0

Open the chart page →

45,363
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
pillow@10.3.0
12.3.0

Open the chart page →

10,145
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@9.2.0
12.3.0

Open the chart page →

2,573
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
pillow@9.5.0
12.3.0

Open the chart page →

2,507
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pillow@12.2.0
12.3.0

Open the chart page →

4,803
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pillow@11.1.0
12.3.0

Open the chart page →

20,900
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pillow@12.2.0
12.3.0

Open the chart page →

4,601
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pillow@11.2.1
12.3.0

Open the chart page →

6,162
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pillow@11.2.1
12.3.0
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.3.0
opencsghq/label-studio:v2.4.0b4e849fcf94a
pillow@11.3.0
12.3.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pillow@11.3.0
12.3.0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
pillow@11.3.0
12.3.0

Open the chart page →

6,632
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
pillow@10.4.0
12.3.0

Open the chart page →

16,604
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pillow@10.1.0
12.3.0

Open the chart page →

6,179
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
no fix listed

Open the chart page →

27,728
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0
pillow@10.2.0-1ubuntu1
12.3.0
no fix listed

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0
pillow@10.2.0-1ubuntu1
12.3.0
no fix listed

Open the chart page →

5,974
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
pillow@9.0.1
pillow@9.0.1-1ubuntu0.3
12.3.0
no fix listed

Open the chart page →

6,172
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pillow@11.3.0
12.3.0

Open the chart page →

2,305
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pillow@12.0.0
12.3.0

Open the chart page →

11,160
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
pillow@9.3.0
12.3.0

Open the chart page →

14,856
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
pillow@11.1.0
12.3.0

Open the chart page →

19,224
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
pillow@9.3.0
12.3.0

Open the chart page →

25,122
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
pillow@10.4.0
12.3.0

Open the chart page →

2,896
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pillow@9.3.0
12.3.0

Open the chart page →

4,085
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pillow@10.4.0
12.3.0

Open the chart page →

2,183
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
pillow@9.0.1
12.3.0

Open the chart page →

1,489
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
12.3.0

Open the chart page →

1,150
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
no fix listed

Open the chart page →

13,551

Container images carrying it

180 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pillow@12.0.0
12.3.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
12.3.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
pillow@11.0.0
12.3.0
1
inventree/inventree:1.5.4a946ec09da3e
pillow@11.1.0
pillow@11.1.0-5+deb13u4
12.3.0
no fix listed
1
kobotoolbox/kobocat:2.022.24ab15679454415
pillow@9.1.0
12.3.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pillow@9.1.0
12.3.0
1
langgenius/dify-api:1.0.0066035f93856
pillow@11.1.0
12.3.0
1
langgenius/dify-api:0.6.11fca918260dd6
pillow@10.3.0
12.3.0
1
linuxserver/babybuddy:1.10.2f7d7c7704249
pillow@9.0.1
12.3.0
1
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
12.3.0
1
linuxserver/calibre-web:0.6.24241009026e6f
pillow@11.3.0
12.3.0
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pillow@11.2.1
12.3.0
1
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0-1ubuntu0.6
no fix listed
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
no fix listed
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
pillow@8.2.0
12.3.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pillow@12.1.1
12.3.0
1
lsstsqre/exposurelog:0.8.079b00fb67a65
pillow@9.0.1
12.3.0
1
mathesar/mathesar:0.12.0091757cb01fe
pillow@12.1.1
12.3.0
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
pillow@11.1.0
12.3.0
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pillow@9.0.1
12.3.0
1
matrixdotorg/synapse:v1.78.0def97fd537d8
pillow@9.4.0
12.3.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pillow@9.5.0
12.3.0
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pillow@8.4.0
12.3.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
pillow@9.2.0
12.3.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
pillow@10.3.0
12.3.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
pillow@12.2.0
12.3.0
1
opea/asr:1.025dd26d9cd09
pillow@10.2.0
12.3.0
1
opea/chatqna:1.038c51b791efa
pillow@10.4.0
12.3.0
1
opea/codegen:1.058f91683892d
pillow@10.4.0
12.3.0
1
opea/codetrans:1.0e2436483b73d
pillow@10.4.0
12.3.0
1
opea/docsum:1.03eaa91849512
pillow@10.4.0
12.3.0
1
opea/guardrails-tgi:1.0262c6048aab8
pillow@10.4.0
12.3.0
1
opea/guardrails-tgi:latestf68bec6a1271
pillow@11.1.0
12.3.0
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
pillow@10.2.0
12.3.0
1
opea/speecht5:1.0249afad3d268
pillow@10.2.0
12.3.0
1
opea/tts:1.0257ae94709e9
pillow@10.2.0
12.3.0
1
opea/web-retriever-chroma:1.0fe08165d7770
pillow@10.4.0
12.3.0
1
openbas/caldera-server:5.1.0a277796d9724
pillow@11.1.0
12.3.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pillow@11.2.1
12.3.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.3.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pillow@11.3.0
12.3.0
1
opencsghq/label-studio:v2.5.047e22aa71870
pillow@11.3.0
12.3.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
pillow@11.3.0
12.3.0
1
opendatacube/explorer:latest120457ffcd69
pillow@10.2.0
pillow@10.2.0-1ubuntu1
12.3.0
no fix listed
1
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
no fix listed
1
opendatacube/wps:latest80df355a660b
pillow@9.0.1
pillow@9.0.1-1ubuntu0.3
12.3.0
no fix listed
1
openmined/syft-backend:0.9.5b72f74a68b32
pillow@11.1.0
12.3.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
pillow@10.2.0
12.3.0
1
prowlercloud/prowler-api:5.31.14f252d579be2
pillow@12.2.0
12.3.0
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
pillow@11.3.0
12.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.