StackRadar

CVE-2026-59204

High

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
179
of 17,781 indexed, latest versions
Container images
180
deployed by those charts
Fix available
1 of 2
affected packages

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

Carried by container images the latest versions of 179 of 17,781 indexed charts deploy, on 180 images.

Affected packageAffected versionsFixed inImages
pillowpypi8.2.0, 8.3.1, 8.3.2, 8.4.0+21 more12.3.0176
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.0.1-1ubuntu0.3+4 moreno fix listed11
OSV records
DEBIAN-CVE-2026-59204GHSA-vjc4-5qp5-m44jUBUNTU-CVE-2026-59204
Also known as
BIT-pillow-2026-59204, PYSEC-2026-3496

Charts affected

179 by stars
ChartLatestAffected imagesRadar Score
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pillow@11.3.0
12.3.0

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
pillow@11.3.0
12.3.0

Open the chart page →

4,499
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
pillow@12.2.0
12.3.0

Open the chart page →

6,207
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
pillow@12.2.0
12.3.0

Open the chart page →

1,577
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
pillow@12.2.0
12.3.0

Open the chart page →

19,560
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
pillow@11.0.0
12.3.0

Open the chart page →

1,713
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
pillow@11.1.0
12.3.0

Open the chart page →

2,817
search-proxysearch-proxy2026.38.01 of 1See more

search-proxy search-proxy 2026.38.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
pillow@12.2.0
12.3.0

Open the chart page →

1,264
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pillow@12.1.1
12.3.0

Open the chart page →

5,201
frigatesmarthallVerified publisher1.0.61 of 1See more

frigate smarthall 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pillow@9.5.0
12.3.0

Open the chart page →

2,243
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
pillow@10.3.0
12.3.0

Open the chart page →

5,565
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pillow@8.4.0
12.3.0

Open the chart page →

8,715
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
pillow@10.2.0
12.3.0

Open the chart page →

4,393
chatqnatest-opea1.0.05 of 11See more

chatqna test-opea 1.0.0

5 of the 11 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
pillow@10.4.0
12.3.0
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.3.0
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.3.0
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.3.0
opea/retriever-redis:1.0eb746b263705
pillow@10.2.0
12.3.0

Open the chart page →

39,090
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
pillow@10.4.0
12.3.0
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.3.0

Open the chart page →

28,814
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
pillow@10.4.0
12.3.0
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.3.0

Open the chart page →

28,385
docsumtest-opea1.0.02 of 5See more

docsum test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
pillow@10.4.0
12.3.0
opea/llm-docsum-tgi:1.002f9e8fa5d71
pillow@10.2.0
12.3.0

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.3.0

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
pillow@10.4.0
12.3.0

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.3.0

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.3.0

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
pillow@10.2.0
12.3.0

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
pillow@10.2.0
12.3.0

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
pillow@10.2.0
12.3.0

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
pillow@10.4.0
12.3.0

Open the chart page →

5,350
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
pillow@9.4.0
12.3.0

Open the chart page →

3,164
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pillow@11.1.0
12.3.0

Open the chart page →

4,768
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
pillow@11.3.0
12.3.0

Open the chart page →

7,628
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pillow@10.2.0
12.3.0

Open the chart page →

7,085

Container images carrying it

180 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pillow@12.0.0
12.3.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
12.3.0
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
pillow@11.0.0
12.3.0
1
inventree/inventree:1.5.4a946ec09da3e
pillow@11.1.0
pillow@11.1.0-5+deb13u4
12.3.0
no fix listed
1
kobotoolbox/kobocat:2.022.24ab15679454415
pillow@9.1.0
12.3.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pillow@9.1.0
12.3.0
1
langgenius/dify-api:1.0.0066035f93856
pillow@11.1.0
12.3.0
1
langgenius/dify-api:0.6.11fca918260dd6
pillow@10.3.0
12.3.0
1
linuxserver/babybuddy:1.10.2f7d7c7704249
pillow@9.0.1
12.3.0
1
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
12.3.0
1
linuxserver/calibre-web:0.6.24241009026e6f
pillow@11.3.0
12.3.0
1
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pillow@11.2.1
12.3.0
1
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0-1ubuntu0.6
no fix listed
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
no fix listed
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
pillow@8.2.0
12.3.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pillow@12.1.1
12.3.0
1
lsstsqre/exposurelog:0.8.079b00fb67a65
pillow@9.0.1
12.3.0
1
mathesar/mathesar:0.12.0091757cb01fe
pillow@12.1.1
12.3.0
1
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
pillow@11.1.0
12.3.0
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pillow@9.0.1
12.3.0
1
matrixdotorg/synapse:v1.78.0def97fd537d8
pillow@9.4.0
12.3.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pillow@9.5.0
12.3.0
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pillow@8.4.0
12.3.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
pillow@9.2.0
12.3.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
pillow@10.3.0
12.3.0
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
pillow@12.2.0
12.3.0
1
opea/asr:1.025dd26d9cd09
pillow@10.2.0
12.3.0
1
opea/chatqna:1.038c51b791efa
pillow@10.4.0
12.3.0
1
opea/codegen:1.058f91683892d
pillow@10.4.0
12.3.0
1
opea/codetrans:1.0e2436483b73d
pillow@10.4.0
12.3.0
1
opea/docsum:1.03eaa91849512
pillow@10.4.0
12.3.0
1
opea/guardrails-tgi:1.0262c6048aab8
pillow@10.4.0
12.3.0
1
opea/guardrails-tgi:latestf68bec6a1271
pillow@11.1.0
12.3.0
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
pillow@10.2.0
12.3.0
1
opea/speecht5:1.0249afad3d268
pillow@10.2.0
12.3.0
1
opea/tts:1.0257ae94709e9
pillow@10.2.0
12.3.0
1
opea/web-retriever-chroma:1.0fe08165d7770
pillow@10.4.0
12.3.0
1
openbas/caldera-server:5.1.0a277796d9724
pillow@11.1.0
12.3.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pillow@11.2.1
12.3.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.3.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pillow@11.3.0
12.3.0
1
opencsghq/label-studio:v2.5.047e22aa71870
pillow@11.3.0
12.3.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
pillow@11.3.0
12.3.0
1
opendatacube/explorer:latest120457ffcd69
pillow@10.2.0
pillow@10.2.0-1ubuntu1
12.3.0
no fix listed
1
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
no fix listed
1
opendatacube/wps:latest80df355a660b
pillow@9.0.1
pillow@9.0.1-1ubuntu0.3
12.3.0
no fix listed
1
openmined/syft-backend:0.9.5b72f74a68b32
pillow@11.1.0
12.3.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
pillow@10.2.0
12.3.0
1
prowlercloud/prowler-api:5.31.14f252d579be2
pillow@12.2.0
12.3.0
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
pillow@11.3.0
12.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.