StackRadar

CVE-2026-59204

High

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
179
of 17,781 indexed, latest versions
Container images
180
deployed by those charts
Fix available
1 of 2
affected packages

Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

Carried by container images the latest versions of 179 of 17,781 indexed charts deploy, on 180 images.

Affected packageAffected versionsFixed inImages
pillowpypi8.2.0, 8.3.1, 8.3.2, 8.4.0+21 more12.3.0176
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.0.1-1ubuntu0.3+4 moreno fix listed11
OSV records
DEBIAN-CVE-2026-59204GHSA-vjc4-5qp5-m44jUBUNTU-CVE-2026-59204
Also known as
BIT-pillow-2026-59204, PYSEC-2026-3496

Charts affected

179 by stars
ChartLatestAffected imagesRadar Score
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
pillow@11.3.0
12.3.0

Open the chart page →

7,201
mlflow-controllermlflow-deployment-controller0.1.81 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pillow@9.4.0
12.3.0

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
pillow@9.3.0
12.3.0

Open the chart page →

5,804
opentelemetry-demoopentelemetry-helmVerified publisher0.41.11 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

1 of the 34 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-chatbot66ba53497f1f
pillow@12.2.0
12.3.0

Open the chart page →

22,420
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
pillow@11.2.1
12.3.0

Open the chart page →

6,873
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
pillow@12.2.0
12.3.0

Open the chart page →

8,158
mealiertomik-helm-chartsVerified publisher0.0.21 of 1See more

mealie rtomik-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
pillow@11.3.0
12.3.0

Open the chart page →

3,929
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0-1ubuntu0.6
no fix listed

Open the chart page →

13,541
sentry-k8ssentry-k8sVerified publisher1.4.11 of 11See more

sentry-k8s sentry-k8s 1.4.1

1 of the 11 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
pillow@12.2.0
12.3.0

Open the chart page →

16,449
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
pillow@11.0.0
12.3.0

Open the chart page →

2,928
streamlit-appstreamlit-appVerified publisher0.2.01 of 1See more

streamlit-app streamlit-app 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
sruthitanneru/pi-sample:ui-lateste565ea454ffd
pillow@11.0.0
12.3.0

Open the chart page →

1,696
synapsesudermanjr1.1.51 of 1See more

synapse sudermanjr 1.1.5

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pillow@9.0.1
12.3.0

Open the chart page →

3,332
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.3.0

Open the chart page →

9,148
verbacapverbacapVerified publisher1.0.71 of 1See more

verbacap verbacap 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/mirio/verbacap:v1.5.084928e2fc4f2
pillow@10.3.0
12.3.0

Open the chart page →

2,233
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
pillow@10.4.0
12.3.0

Open the chart page →

6,324
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
pillow@12.2.0
12.3.0

Open the chart page →

5,817
mathesarandrenarchyVerified publisher1.8.01 of 1See more

mathesar andrenarchy 1.8.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
mathesar/mathesar:0.12.0091757cb01fe
pillow@12.1.1
12.3.0

Open the chart page →

7,239
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pillow@12.1.1
12.3.0

Open the chart page →

5,558
pgadminappscodeVerified publisher2026.3.301 of 1See more

pgadmin appscode 2026.3.30

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:9.11.050700ac17936
pillow@12.0.0
12.3.0

Open the chart page →

1,565
pgadminarunalakmalVerified publisher0.1.01 of 1See more

pgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
12.3.0

Open the chart page →

2,418
swdpgadminarunalakmalVerified publisher0.1.01 of 1See more

swdpgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
12.3.0

Open the chart page →

2,418
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
12.3.0

Open the chart page →

10,061
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
pillow@10.2.0
12.3.0
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pillow@10.3.0
12.3.0
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pillow@9.5.0
12.3.0

Open the chart page →

45,363
baserowblackbird-cloudVerified publisher1.0.171 of 6See more

baserow blackbird-cloud 1.0.17

1 of the 6 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
baserow/backend:1.31.1e0b3c8130b91
pillow@10.3.0
12.3.0

Open the chart page →

10,145
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@9.2.0
12.3.0

Open the chart page →

2,573
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
pillow@9.5.0
12.3.0

Open the chart page →

2,507
kitchenowlchart-kitchenowl0.1.121 of 2See more

kitchenowl chart-kitchenowl 0.1.12

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pillow@12.2.0
12.3.0

Open the chart page →

4,803
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pillow@11.1.0
12.3.0

Open the chart page →

20,900
galaxycloudve6.8.61 of 3See more

galaxy cloudve 6.8.6

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
pillow@12.2.0
12.3.0

Open the chart page →

4,601
pulsarcloudve0.2.01 of 2See more

pulsar cloudve 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pillow@11.2.1
12.3.0

Open the chart page →

6,162
csghubcsghubVerified publisher2.4.33 of 34See more

csghub csghub 2.4.3

3 of the 34 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pillow@11.2.1
12.3.0
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.3.0
opencsghq/label-studio:v2.4.0b4e849fcf94a
pillow@11.3.0
12.3.0

Open the chart page →

58,897
csgshipcsghubVerified publisher0.4.61 of 10See more

csgship csghub 0.4.6

1 of the 10 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pillow@11.3.0
12.3.0

Open the chart page →

11,335
dataflowcsghubVerified publisher2.5.01 of 7See more

dataflow csghub 2.5.0

1 of the 7 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
pillow@11.3.0
12.3.0

Open the chart page →

6,632
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
pillow@10.4.0
12.3.0

Open the chart page →

16,604
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
pillow@10.1.0
12.3.0

Open the chart page →

6,179
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
no fix listed

Open the chart page →

27,728
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0
pillow@10.2.0-1ubuntu1
12.3.0
no fix listed

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0
pillow@10.2.0-1ubuntu1
12.3.0
no fix listed

Open the chart page →

5,974
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
pillow@9.0.1
pillow@9.0.1-1ubuntu0.3
12.3.0
no fix listed

Open the chart page →

6,172
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pillow@11.3.0
12.3.0

Open the chart page →

2,305
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pillow@12.0.0
12.3.0

Open the chart page →

11,160
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
pillow@9.3.0
12.3.0

Open the chart page →

14,856
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
pillow@11.1.0
12.3.0

Open the chart page →

19,224
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
pillow@9.3.0
12.3.0

Open the chart page →

25,122
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
pillow@10.4.0
12.3.0

Open the chart page →

2,896
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pillow@9.3.0
12.3.0

Open the chart page →

4,085
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pillow@10.4.0
12.3.0

Open the chart page →

2,183
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
pillow@9.0.1
12.3.0

Open the chart page →

1,489
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
12.3.0

Open the chart page →

1,150
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-59204.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
no fix listed

Open the chart page →

13,551

Container images carrying it

180 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opea/llm-tgi:1.00c25aab3f106
pillow@10.4.0
12.3.0
4
apache/superset:6.1.0:latest16b50bbef664
pillow@11.3.0
12.3.0
3
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
12.3.0
3
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@9.2.0
12.3.0
2
opea/embedding-tei:1.05c9639de61c1
pillow@10.4.0
12.3.0
2
opea/reranking-tei:1.0e48613afb191
pillow@10.4.0
12.3.0
2
opea/retriever-redis:1.0eb746b263705
pillow@10.2.0
12.3.0
2
opendatacube/ows:latest668cbb41473c
pillow@10.2.0
pillow@10.2.0-1ubuntu1
12.3.0
no fix listed
2
safeglobal/safe-config-service:latest09a5e495c219
pillow@12.2.0
12.3.0
2
taigaio/taiga-back:latest4beed8f62c9f
pillow@12.0.0
12.3.0
2
aibrix/metadata-service:v0.7.063fb81a64377
pillow@12.2.0
12.3.0
1
allegroai/clearml:2.0.0-613713ae38f7daf
pillow@11.0.0
12.3.0
1
allegroai/clearml-serving-inference:1.3.0fca885e8cfc6
pillow@9.4.0
12.3.0
1
allegroai/clearml-serving-statistics:1.3.0c58d9da7bdf8
pillow@9.4.0
12.3.0
1
anujdatar/cups:25.07.01685df04a643b
pillow@9.4.0
pillow@9.4.0-1.1+deb12u1
12.3.0
no fix listed
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
pillow@9.1.0
12.3.0
1
apache/superset:4.0.1ab9467fd712c
pillow@10.2.0
12.3.0
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pillow@10.4.0
12.3.0
1
aristidetm/basic-notebook:3.6.5469dbc951224
pillow@10.4.0
12.3.0
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
pillow@10.2.0
12.3.0
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
pillow@10.3.0
12.3.0
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pillow@9.5.0
12.3.0
1
baserow/backend:1.31.1e0b3c8130b91
pillow@10.3.0
12.3.0
1
baserow/baserow:1.30.1df0c42eb67e8
pillow@10.3.0
12.3.0
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pillow@12.0.0
12.3.0
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
pillow@7.0.0-4ubuntu0.5
no fix listed
1
bmeares/meerschaum:2.8.48e9c5bacaa82
pillow@11.1.0
12.3.0
1
bnjbvr/kresus:0.22.137e216b182c8
pillow@11.0.0
12.3.0
1
buntha/mlflow:2.1.1154542cc3083
pillow@9.3.0
12.3.0
1
camerahub/camerahub:0.36.23a5af37dd6e1b
pillow@9.5.0
12.3.0
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
pillow@12.2.0
12.3.0
1
copyparty/ac:1.19.200a0a8605062c
pillow@11.2.1
12.3.0
1
datamate/seafile-professional:11.0.202dd66b722464
pillow@10.2.0
12.3.0
1
deconzcommunity/deconz:2.29.2062de2362641
pillow@9.4.0
pillow@9.4.0-1.1+deb12u1
12.3.0
no fix listed
1
dpage/pgadmin4:7.537946e4f3e7b
pillow@9.5.0
12.3.0
1
dpage/pgadmin4:9.11.050700ac17936
pillow@12.0.0
12.3.0
1
dpage/pgadmin4:9.252cb72a9e3da
pillow@11.1.0
12.3.0
1
dpage/pgadmin4:8.13561c1f8f99f2
pillow@11.0.0
12.3.0
1
esphome/esphome:2024.3.09ab8cc88b28c
pillow@10.2.0
12.3.0
1
esphome/esphome:2024.12.2b2c6322700ac
pillow@10.4.0
12.3.0
1
esphome/esphome:2025.3.0def8b6e4f517
pillow@10.4.0
12.3.0
1
evk02/mlflow:2.2.1ef6ff257ef35
pillow@9.4.0
12.3.0
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pillow@9.3.0
12.3.0
1
galaxy/pulsar-kubernetes:0.15.7e50a890e24c9
pillow@11.2.1
12.3.0
1
heartexlabs/label-studio:latestaa461572e8f9
pillow@12.1.1
12.3.0
1
hhyo/archery:v1.9.11aa41843419e
pillow@9.0.1
12.3.0
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
pillow@8.4.0
12.3.0
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
pillow@10.0.1
12.3.0
1
homeassistant/home-assistant:2026.75a531753cea9
pillow@12.2.0
12.3.0
1
homeassistant/home-assistant:2023.12.48d000332b09b
pillow@10.1.0
12.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.