StackRadar

CVE-2026-59204

High

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
179
of 17,781 indexed, latest versions
Container images
180
deployed by those charts
Fix available
1 of 2
affected packages

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

Carried by container images the latest versions of 179 of 17,781 indexed charts deploy, on 180 images.

Affected packageAffected versionsFixed inImages
pillowpypi8.2.0, 8.3.1, 8.3.2, 8.4.0+21 more12.3.0176
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.0.1-1ubuntu0.3+4 moreno fix listed11
OSV records
DEBIAN-CVE-2026-59204GHSA-vjc4-5qp5-m44jUBUNTU-CVE-2026-59204
Also known as
BIT-pillow-2026-59204, PYSEC-2026-3496

Charts affected

179 by stars
ChartLatestAffected imagesRadar Score
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pillow@11.3.0
12.3.0

Open the chart page →

10,605
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
pillow@11.3.0
12.3.0

Open the chart page →

4,499
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
pillow@12.2.0
12.3.0

Open the chart page →

6,207
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
pillow@12.2.0
12.3.0

Open the chart page →

1,577
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
pillow@12.2.0
12.3.0

Open the chart page →

19,560
pgadminsb-helm-charts0.3.01 of 1See more

pgadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:8.13561c1f8f99f2
pillow@11.0.0
12.3.0

Open the chart page →

1,713
scapyscapy-containerised0.3.41 of 2See more

scapy scapy-containerised 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
saidsef/scapy-containerised:v2025.02f17f7c435891
pillow@11.1.0
12.3.0

Open the chart page →

2,817
search-proxysearch-proxy2026.38.01 of 1See more

search-proxy search-proxy 2026.38.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
pillow@12.2.0
12.3.0

Open the chart page →

1,264
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pillow@12.1.1
12.3.0

Open the chart page →

5,201
frigatesmarthallVerified publisher1.0.61 of 1See more

frigate smarthall 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pillow@9.5.0
12.3.0

Open the chart page →

2,243
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
pillow@10.3.0
12.3.0

Open the chart page →

5,565
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pillow@8.4.0
12.3.0

Open the chart page →

8,715
asrtest-opea1.0.01 of 1See more

asr test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/asr:1.025dd26d9cd09
pillow@10.2.0
12.3.0

Open the chart page →

4,393
chatqnatest-opea1.0.05 of 11See more

chatqna test-opea 1.0.0

5 of the 11 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/chatqna:1.038c51b791efa
pillow@10.4.0
12.3.0
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.3.0
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.3.0
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.3.0
opea/retriever-redis:1.0eb746b263705
pillow@10.2.0
12.3.0

Open the chart page →

39,090
codegentest-opea1.0.02 of 5See more

codegen test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/codegen:1.058f91683892d
pillow@10.4.0
12.3.0
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.3.0

Open the chart page →

28,814
codetranstest-opea1.0.02 of 5See more

codetrans test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/codetrans:1.0e2436483b73d
pillow@10.4.0
12.3.0
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.3.0

Open the chart page →

28,385
docsumtest-opea1.0.02 of 5See more

docsum test-opea 1.0.0

2 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/docsum:1.03eaa91849512
pillow@10.4.0
12.3.0
opea/llm-docsum-tgi:1.002f9e8fa5d71
pillow@10.2.0
12.3.0

Open the chart page →

28,858
embedding-usvctest-opea1.0.01 of 1See more

embedding-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.3.0

Open the chart page →

5,185
guardrails-usvctest-opea1.0.01 of 1See more

guardrails-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/guardrails-tgi:1.0262c6048aab8
pillow@10.4.0
12.3.0

Open the chart page →

5,221
llm-uservicetest-opea1.0.01 of 1See more

llm-uservice test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.3.0

Open the chart page →

4,720
reranking-usvctest-opea1.0.01 of 1See more

reranking-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.3.0

Open the chart page →

4,985
retriever-usvctest-opea1.0.01 of 1See more

retriever-usvc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/retriever-redis:1.0eb746b263705
pillow@10.2.0
12.3.0

Open the chart page →

5,198
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
pillow@10.2.0
12.3.0

Open the chart page →

9,616
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
pillow@10.2.0
12.3.0

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
pillow@10.4.0
12.3.0

Open the chart page →

5,350
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
pillow@9.4.0
12.3.0

Open the chart page →

3,164
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.252cb72a9e3da
pillow@11.1.0
12.3.0

Open the chart page →

4,768
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
pillow@11.3.0
12.3.0

Open the chart page →

7,628
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pillow@10.2.0
12.3.0

Open the chart page →

7,085

Container images carrying it

180 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
pillow@12.1.1
12.3.0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pillow@10.2.0
12.3.0
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pillow@11.3.0
12.3.0
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
pillow@10.3.0
12.3.0
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
pillow@12.0.0
12.3.0
1
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pillow@10.3.0
12.3.0
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
pillow@11.3.0
12.3.0
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pillow@12.2.0
12.3.0
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pillow@12.1.1
12.3.0
1
ghcr.io/open-telemetry/demo:3.0.0-chatbot66ba53497f1f
pillow@12.2.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
pillow@10.4.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
pillow@11.3.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
pillow@11.3.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
pillow@11.3.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
pillow@9.2.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
pillow@10.1.0
12.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pillow@11.3.0
12.3.0
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
pillow@12.2.0
12.3.0
1
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pillow@10.4.0
12.3.0
1
ghcr.io/unique-ag/ai/search-proxy:2026.38.0aa6699b027bb
pillow@12.2.0
12.3.0
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
pillow@11.2.1
12.3.0
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pillow@9.4.0
pillow@9.4.0-1.1+b1
12.3.0
no fix listed
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pillow@12.2.0
12.3.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
pillow@10.3.0
12.3.0
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
pillow@11.1.0
12.3.0
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
pillow@11.1.0
12.3.0
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
pillow@12.0.0
12.3.0
1
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pillow@12.0.0
12.3.0
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
pillow@10.3.0
12.3.0
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
pillow@12.2.0
12.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.