StackRadar

CVE-2026-59204

High

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
179
of 17,781 indexed, latest versions
Container images
180
deployed by those charts
Fix available
1 of 2
affected packages

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

Carried by container images the latest versions of 179 of 17,781 indexed charts deploy, on 180 images.

Affected packageAffected versionsFixed inImages
pillowpypi8.2.0, 8.3.1, 8.3.2, 8.4.0+21 more12.3.0176
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.0.1-1ubuntu0.3+4 moreno fix listed11
OSV records
DEBIAN-CVE-2026-59204GHSA-vjc4-5qp5-m44jUBUNTU-CVE-2026-59204
Also known as
BIT-pillow-2026-59204, PYSEC-2026-3496

Charts affected

179 by stars
ChartLatestAffected imagesRadar Score
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
pillow@11.3.0
12.3.0

Open the chart page →

7,201
mlflow-controllermlflow-deployment-controller0.1.81 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pillow@9.4.0
12.3.0

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
pillow@9.3.0
12.3.0

Open the chart page →

5,804
opentelemetry-demoopentelemetry-helmVerified publisher0.41.11 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

1 of the 34 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-chatbot66ba53497f1f
pillow@12.2.0
12.3.0

Open the chart page →

22,420
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
pillow@11.2.1
12.3.0

Open the chart page →

6,873
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
pillow@12.2.0
12.3.0

Open the chart page →

8,158
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pillow@11.3.0
12.3.0

Open the chart page →

3,929
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0-1ubuntu0.6
no fix listed

Open the chart page →

13,541
sentry-k8ssentry-k8sVerified publisher1.4.11 of 11See more

sentry-k8s sentry-k8s 1.4.1

1 of the 11 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
pillow@12.2.0
12.3.0

Open the chart page →

16,449
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
pillow@11.0.0
12.3.0

Open the chart page →

2,928
streamlit-appstreamlit-appVerified publisher0.2.01 of 1See more

streamlit-app streamlit-app 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
sruthitanneru/pi-sample:ui-lateste565ea454ffd
pillow@11.0.0
12.3.0

Open the chart page →

1,696
synapsesudermanjr1.1.51 of 1See more

synapse sudermanjr 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pillow@9.0.1
12.3.0

Open the chart page →

3,332
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.3.0

Open the chart page →

9,148
verbacapverbacapVerified publisher1.0.71 of 1See more

verbacap verbacap 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pillow@10.3.0
12.3.0

Open the chart page →

2,233
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
pillow@10.4.0
12.3.0

Open the chart page →

6,324
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pillow@12.2.0
12.3.0

Open the chart page →

5,817
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
pillow@12.1.1
12.3.0

Open the chart page →

7,239
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pillow@12.1.1
12.3.0

Open the chart page →

5,558
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
pillow@12.0.0
12.3.0

Open the chart page →

1,565
pgadminarunalakmalVerified publisher0.1.01 of 1See more

pgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
12.3.0

Open the chart page →

2,418
swdpgadminarunalakmalVerified publisher0.1.01 of 1See more

swdpgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
12.3.0

Open the chart page →

2,418
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
12.3.0

Open the chart page →

10,061
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
pillow@10.2.0
12.3.0
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pillow@10.3.0
12.3.0
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pillow@9.5.0
12.3.0

Open the chart page →

45,363
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
pillow@10.3.0
12.3.0

Open the chart page →

10,145
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@9.2.0
12.3.0

Open the chart page →

2,573
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
pillow@9.5.0
12.3.0

Open the chart page →

2,507
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pillow@12.2.0
12.3.0

Open the chart page →

4,803
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pillow@11.1.0
12.3.0

Open the chart page →

20,900
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pillow@12.2.0
12.3.0

Open the chart page →

4,601
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pillow@11.2.1
12.3.0

Open the chart page →

6,162
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pillow@11.2.1
12.3.0
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.3.0
opencsghq/label-studio:v2.4.0b4e849fcf94a
pillow@11.3.0
12.3.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pillow@11.3.0
12.3.0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
pillow@11.3.0
12.3.0

Open the chart page →

6,632
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
pillow@10.4.0
12.3.0

Open the chart page →

16,604
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pillow@10.1.0
12.3.0

Open the chart page →

6,179
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
no fix listed

Open the chart page →

27,728
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0
pillow@10.2.0-1ubuntu1
12.3.0
no fix listed

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0
pillow@10.2.0-1ubuntu1
12.3.0
no fix listed

Open the chart page →

5,974
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
pillow@9.0.1
pillow@9.0.1-1ubuntu0.3
12.3.0
no fix listed

Open the chart page →

6,172
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pillow@11.3.0
12.3.0

Open the chart page →

2,305
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pillow@12.0.0
12.3.0

Open the chart page →

11,160
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
pillow@9.3.0
12.3.0

Open the chart page →

14,856
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
pillow@11.1.0
12.3.0

Open the chart page →

19,224
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
pillow@9.3.0
12.3.0

Open the chart page →

25,122
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
pillow@10.4.0
12.3.0

Open the chart page →

2,896
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pillow@9.3.0
12.3.0

Open the chart page →

4,085
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pillow@10.4.0
12.3.0

Open the chart page →

2,183
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
pillow@9.0.1
12.3.0

Open the chart page →

1,489
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
12.3.0

Open the chart page →

1,150
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
no fix listed

Open the chart page →

13,551

Container images carrying it

180 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
pillow@12.1.1
12.3.0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pillow@10.2.0
12.3.0
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pillow@11.3.0
12.3.0
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
pillow@10.3.0
12.3.0
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pillow@12.0.0
12.3.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pillow@10.3.0
12.3.0
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
pillow@11.3.0
12.3.0
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pillow@12.2.0
12.3.0
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pillow@12.1.1
12.3.0
1
ghcr.io/open-telemetry/demo:3.0.0-chatbot66ba53497f1f
pillow@12.2.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
pillow@10.4.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
pillow@11.3.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pillow@11.3.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
pillow@11.3.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
pillow@9.2.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
pillow@10.1.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pillow@11.3.0
12.3.0
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
pillow@12.2.0
12.3.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pillow@10.4.0
12.3.0
1
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
pillow@12.2.0
12.3.0
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
pillow@11.2.1
12.3.0
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pillow@9.4.0
pillow@9.4.0-1.1+b1
12.3.0
no fix listed
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pillow@12.2.0
12.3.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
pillow@10.3.0
12.3.0
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
pillow@11.1.0
12.3.0
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
pillow@11.1.0
12.3.0
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
pillow@12.0.0
12.3.0
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pillow@12.0.0
12.3.0
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
pillow@10.3.0
12.3.0
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
pillow@12.2.0
12.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.