StackRadar

CVE-2026-59204

High

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
179
of 17,787 indexed, latest versions
Container images
180
deployed by those charts
Fix available
1 of 2
affected packages

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

Carried by container images the latest versions of 179 of 17,787 indexed charts deploy, on 180 images.

Affected packageAffected versionsFixed inImages
pillowpypi8.2.0, 8.3.1, 8.3.2, 8.4.0+21 more12.3.0176
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.0.1-1ubuntu0.3+4 moreno fix listed11
OSV records
DEBIAN-CVE-2026-59204GHSA-vjc4-5qp5-m44jUBUNTU-CVE-2026-59204
Also known as
BIT-pillow-2026-59204, PYSEC-2026-3496

Charts affected

179 by stars
ChartLatestAffected imagesRadar Score
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pillow@8.3.1
12.3.0

Open the chart page →

24,355
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pillow@12.0.0
12.3.0

Open the chart page →

8,955
esphomehelm-chart-roeiVerified publisher2025.3.01 of 1See more

esphome helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
esphome/esphome:2025.3.0def8b6e4f517
pillow@10.4.0
12.3.0

Open the chart page →

6,014
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
pillow@11.1.0
12.3.0

Open the chart page →

4,646
supersethelm-charts-nr1.1.31 of 1See more

superset helm-charts-nr 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pillow@11.3.0
12.3.0

Open the chart page →

2,214
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
pillow@12.2.0
12.3.0

Open the chart page →

11,080
supersethelmforgeVerified publisher1.3.61 of 5See more

superset helmforge 1.3.6

1 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
apache/superset:6.1.016b50bbef664
pillow@11.3.0
12.3.0

Open the chart page →

5,649
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
pillow@11.1.0
12.3.0

Open the chart page →

25,099
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
pillow@10.1.0
12.3.0

Open the chart page →

14,629
ilum-streamlitilumVerified publisher0.1.01 of 1See more

ilum-streamlit ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pillow@12.0.0
12.3.0

Open the chart page →

2,748
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
12.3.0

Open the chart page →

6,502
frigateimprowisedVerified publisher1.1.01 of 1See more

frigate improwised 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
pillow@10.2.0
12.3.0

Open the chart page →

2,159
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
pillow@11.1.0
12.3.0

Open the chart page →

5,069
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
pillow@12.1.1
12.3.0

Open the chart page →

3,157
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
pillow@11.0.0
12.3.0

Open the chart page →

16,558
inventreeinventreeOfficialVerified publisher0.4.281 of 2See more

inventree inventree 0.4.28

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
pillow@11.1.0
pillow@11.1.0-5+deb13u4
12.3.0
no fix listed

Open the chart page →

5,757
twitch-channel-points-minerjacobcolvinVerified publisher0.1.01 of 1See more

twitch-channel-points-miner jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
pillow@10.0.0
12.3.0

Open the chart page →

1,088
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
pillow@9.4.0
pillow@9.4.0-1.1+deb12u1
12.3.0
no fix listed

Open the chart page →

10,816
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
pillow@12.2.0
12.3.0

Open the chart page →

5,066
bazarrk8s-home-lab-repo11.3.21 of 1See more

bazarr k8s-home-lab-repo 11.3.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
pillow@12.2.0
12.3.0

Open the chart page →

1,795
beetsk8s-home-lab-repo3.1.11 of 1See more

beets k8s-home-lab-repo 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
pillow@11.2.1
12.3.0

Open the chart page →

2,732
frigatek8s-home-lab-repo9.1.11 of 1See more

frigate k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@9.2.0
12.3.0

Open the chart page →

2,370
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pillow@11.3.0
12.3.0

Open the chart page →

8,990
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pillow@12.1.1
12.3.0

Open the chart page →

6,836
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
pillow@10.0.1
12.3.0

Open the chart page →

6,446
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pillow@10.4.0
12.3.0

Open the chart page →

8,455
delugelinkding0.2.31 of 1See more

deluge linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pillow@11.2.1
12.3.0

Open the chart page →

1,432
calendar-apiliturgical0.1.51 of 1See more

calendar-api liturgical 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
pillow@11.3.0
12.3.0

Open the chart page →

1,557
liturgical-apiliturgical0.2.111 of 1See more

liturgical-api liturgical 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
pillow@12.1.1
12.3.0

Open the chart page →

1,004
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
pillow@12.2.0
12.3.0

Open the chart page →

2,450
exposureloglsst-sqre0.2.11 of 1See more

exposurelog lsst-sqre 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
lsstsqre/exposurelog:0.8.079b00fb67a65
pillow@9.0.1
12.3.0

Open the chart page →

2,078
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pillow@10.2.0
12.3.0

Open the chart page →

4,659
meerschaummeerschaumVerified publisher0.2.01 of 1See more

meerschaum meerschaum 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
bmeares/meerschaum:2.8.48e9c5bacaa82
pillow@11.1.0
12.3.0

Open the chart page →

5,849
mlflowmondata-helm-chartsVerified publisher0.2.31 of 1See more

mlflow mondata-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pillow@9.5.0
12.3.0

Open the chart page →

3,811
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pillow@8.4.0
12.3.0

Open the chart page →

8,556
paperless-ngxmt1905027.6.141 of 4See more

paperless-ngx mt190502 7.6.14

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
pillow@11.3.0
12.3.0

Open the chart page →

11,860
szurubooru-servermy0nVerified publisher0.2.51 of 3See more

szurubooru-server my0n 0.2.5

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
szurubooru/server:2.5accf2ad9fbc3
pillow@11.2.1
12.3.0

Open the chart page →

1,044
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
pillow@9.4.0
12.3.0

Open the chart page →

5,456
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
pillow@11.1.0
12.3.0

Open the chart page →

7,413
chatbot-ai-sampleopenshift0.1.61 of 4See more

chatbot-ai-sample openshift 0.1.6

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
pillow@10.3.0
12.3.0

Open the chart page →

18,991
ctfdpascaliskeVerified publisher2.0.01 of 1See more

ctfd pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/ctfd/ctfd:3.8.2870e396fddf8
pillow@11.3.0
12.3.0

Open the chart page →

2,383
home-assistantpascaliskeVerified publisher0.1.11 of 1See more

home-assistant pascaliske 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
pillow@12.0.0
12.3.0

Open the chart page →

4,788
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
pillow@9.2.0
12.3.0

Open the chart page →

22,146
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
pillow@11.3.0
12.3.0

Open the chart page →

4,614
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
pillow@9.4.0
pillow@9.4.0-1.1+deb12u1
12.3.0
no fix listed

Open the chart page →

7,691
esphomeretsamedocVerified publisher2026.2.51 of 1See more

esphome retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
esphome/esphome:2024.3.09ab8cc88b28c
pillow@10.2.0
12.3.0

Open the chart page →

6,562
rhbk-neurofacerhbk-neurofaceVerified publisher1.0.01 of 4See more

rhbk-neuroface rhbk-neuroface 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
pillow@11.1.0
12.3.0

Open the chart page →

3,837
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
pillow@11.0.0
12.3.0

Open the chart page →

15,623
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
pillow@11.1.0
12.3.0

Open the chart page →

9,275
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
pillow@12.2.0
12.3.0

Open the chart page →

7,491

Container images carrying it

180 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pillow@12.0.0
12.3.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
12.3.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
pillow@11.0.0
12.3.0
1
inventree/inventree:1.5.4a946ec09da3e
pillow@11.1.0
pillow@11.1.0-5+deb13u4
12.3.0
no fix listed
1
kobotoolbox/kobocat:2.022.24ab15679454415
pillow@9.1.0
12.3.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pillow@9.1.0
12.3.0
1
langgenius/dify-api:1.0.0066035f93856
pillow@11.1.0
12.3.0
1
langgenius/dify-api:0.6.11fca918260dd6
pillow@10.3.0
12.3.0
1
linuxserver/babybuddy:1.10.2f7d7c7704249
pillow@9.0.1
12.3.0
1
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
12.3.0
1
linuxserver/calibre-web:0.6.24241009026e6f
pillow@11.3.0
12.3.0
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pillow@11.2.1
12.3.0
1
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0-1ubuntu0.6
no fix listed
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
no fix listed
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
pillow@8.2.0
12.3.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pillow@12.1.1
12.3.0
1
lsstsqre/exposurelog:0.8.079b00fb67a65
pillow@9.0.1
12.3.0
1
mathesar/mathesar:0.12.0091757cb01fe
pillow@12.1.1
12.3.0
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
pillow@11.1.0
12.3.0
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pillow@9.0.1
12.3.0
1
matrixdotorg/synapse:v1.78.0def97fd537d8
pillow@9.4.0
12.3.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pillow@9.5.0
12.3.0
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pillow@8.4.0
12.3.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
pillow@9.2.0
12.3.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
pillow@10.3.0
12.3.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
pillow@12.2.0
12.3.0
1
opea/asr:1.025dd26d9cd09
pillow@10.2.0
12.3.0
1
opea/chatqna:1.038c51b791efa
pillow@10.4.0
12.3.0
1
opea/codegen:1.058f91683892d
pillow@10.4.0
12.3.0
1
opea/codetrans:1.0e2436483b73d
pillow@10.4.0
12.3.0
1
opea/docsum:1.03eaa91849512
pillow@10.4.0
12.3.0
1
opea/guardrails-tgi:1.0262c6048aab8
pillow@10.4.0
12.3.0
1
opea/guardrails-tgi:latestf68bec6a1271
pillow@11.1.0
12.3.0
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
pillow@10.2.0
12.3.0
1
opea/speecht5:1.0249afad3d268
pillow@10.2.0
12.3.0
1
opea/tts:1.0257ae94709e9
pillow@10.2.0
12.3.0
1
opea/web-retriever-chroma:1.0fe08165d7770
pillow@10.4.0
12.3.0
1
openbas/caldera-server:5.1.0a277796d9724
pillow@11.1.0
12.3.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pillow@11.2.1
12.3.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.3.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pillow@11.3.0
12.3.0
1
opencsghq/label-studio:v2.5.047e22aa71870
pillow@11.3.0
12.3.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
pillow@11.3.0
12.3.0
1
opendatacube/explorer:latest120457ffcd69
pillow@10.2.0
pillow@10.2.0-1ubuntu1
12.3.0
no fix listed
1
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
no fix listed
1
opendatacube/wps:latest80df355a660b
pillow@9.0.1
pillow@9.0.1-1ubuntu0.3
12.3.0
no fix listed
1
openmined/syft-backend:0.9.5b72f74a68b32
pillow@11.1.0
12.3.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
pillow@10.2.0
12.3.0
1
prowlercloud/prowler-api:5.31.14f252d579be2
pillow@12.2.0
12.3.0
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
pillow@11.3.0
12.3.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.