CVE-2026-59204
HighAdvisory
Published 14 Jul 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.7
- base score, highest
- EPSS
- 0.004
- 33rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 179
- of 17,781 indexed, latest versions
- Container images
- 180
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
Carried by container images the latest versions of 179 of 17,781 indexed charts deploy, on 180 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pillowpypi | 8.2.0, 8.3.1, 8.3.2, 8.4.0+21 more | 12.3.0 | 176 |
| pillowdeb | 5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.0.1-1ubuntu0.3+4 more | no fix listed | 11 |
- OSV records
- DEBIAN-CVE-2026-59204GHSA-vjc4-5qp5-m44jUBUNTU-CVE-2026-59204
- Also known as
- BIT-pillow-2026-59204, PYSEC-2026-3496
Charts affected
179 by stars
Container images carrying it
180 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ilum/ | ce5dcdeb22ba | pillow | 12.3.0 | 1 |
| improwised/ | 97280b55cbd4 | pillow | 12.3.0 | 1 |
| intelowlproject/ | 0b22e547ea6b | pillow | 12.3.0 | 1 |
| inventree/ | a946ec09da3e | pillow pillow | 12.3.0 no fix listed | 1 |
| kobotoolbox/ | b15679454415 | pillow | 12.3.0 | 1 |
| kobotoolbox/ | bcacc01bccd4 | pillow | 12.3.0 | 1 |
| langgenius/ | 066035f93856 | pillow | 12.3.0 | 1 |
| langgenius/ | fca918260dd6 | pillow | 12.3.0 | 1 |
| linuxserver/ | f7d7c7704249 | pillow | 12.3.0 | 1 |
| linuxserver/ | e36d16f7341c | pillow | 12.3.0 | 1 |
| linuxserver/ | 241009026e6f | pillow | 12.3.0 | 1 |
| linuxserver/ | 052eac68ccc0 | pillow | 12.3.0 | 1 |
| linuxserver/ | 0ac871624394 | pillow | no fix listed | 1 |
| linuxserver/ | 2ce561a95e7b | pillow | no fix listed | 1 |
| linuxserver/ | f93d2560e233 | pillow | 12.3.0 | 1 |
| litellm/ | 09b217802ded | pillow | 12.3.0 | 1 |
| lsstsqre/ | 79b00fb67a65 | pillow | 12.3.0 | 1 |
| mathesar/ | 091757cb01fe | pillow | 12.3.0 | 1 |
| matrixdotorg/ | c3c4a9de2a0b | pillow | 12.3.0 | 1 |
| matrixdotorg/ | cb89c0f17ba1 | pillow | 12.3.0 | 1 |
| matrixdotorg/ | def97fd537d8 | pillow | 12.3.0 | 1 |
| mondata/ | 6f94c6caf8bf | pillow | 12.3.0 | 1 |
| moreillon/ | bacb2ddd8394 | pillow | 12.3.0 | 1 |
| netboxcommunity/ | 3d652dca5351 | pillow | 12.3.0 | 1 |
| netboxcommunity/ | 9bf83b350a89 | pillow | 12.3.0 | 1 |
| networktocode/ | ed484336b1ad | pillow | 12.3.0 | 1 |
| opea/ | 25dd26d9cd09 | pillow | 12.3.0 | 1 |
| opea/ | 38c51b791efa | pillow | 12.3.0 | 1 |
| opea/ | 58f91683892d | pillow | 12.3.0 | 1 |
| opea/ | e2436483b73d | pillow | 12.3.0 | 1 |
| opea/ | 3eaa91849512 | pillow | 12.3.0 | 1 |
| opea/ | 262c6048aab8 | pillow | 12.3.0 | 1 |
| opea/ | f68bec6a1271 | pillow | 12.3.0 | 1 |
| opea/ | 02f9e8fa5d71 | pillow | 12.3.0 | 1 |
| opea/ | 249afad3d268 | pillow | 12.3.0 | 1 |
| opea/ | 257ae94709e9 | pillow | 12.3.0 | 1 |
| opea/ | fe08165d7770 | pillow | 12.3.0 | 1 |
| openbas/ | a277796d9724 | pillow | 12.3.0 | 1 |
| opencsghq/ | 2f03fead54db | pillow | 12.3.0 | 1 |
| opencsghq/ | af7191a9cf8a | pillow | 12.3.0 | 1 |
| opencsghq/ | c36a5bac3cf0 | pillow | 12.3.0 | 1 |
| opencsghq/ | 47e22aa71870 | pillow | 12.3.0 | 1 |
| opencsghq/ | b4e849fcf94a | pillow | 12.3.0 | 1 |
| opendatacube/ | 120457ffcd69 | pillow pillow | 12.3.0 no fix listed | 1 |
| opendatacube/ | 1b90cdf68831 | pillow | no fix listed | 1 |
| opendatacube/ | 80df355a660b | pillow pillow | 12.3.0 no fix listed | 1 |
| openmined/ | b72f74a68b32 | pillow | 12.3.0 | 1 |
| pangeo/ | 5fbe688a4f80 | pillow | 12.3.0 | 1 |
| prowlercloud/ | 4f252d579be2 | pillow | 12.3.0 | 1 |
| pschiffe/ | 37ebba8c2b8f | pillow | 12.3.0 | 1 |