StackRadar

CVE-2026-59205

High

Advisory

Published 14 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
200
of 17,781 indexed, latest versions
Container images
202
deployed by those charts
Fix available
1 of 2
affected packages

Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch

Carried by container images the latest versions of 200 of 17,781 indexed charts deploy, on 202 images.

Affected packageAffected versionsFixed inImages
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+34 more12.3.0202
pillowdeb5.1.0-1, 5.1.0-1ubuntu0.6, 7.0.0-4ubuntu0.5, 9.0.1-1ubuntu0.3+4 moreno fix listed11
OSV records
DEBIAN-CVE-2026-59205GHSA-9hw9-ch79-4vh6UBUNTU-CVE-2026-59205
Also known as
BIT-pillow-2026-59205, PYSEC-2026-3453

Charts affected

200 by stars
ChartLatestAffected imagesRadar Score
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
pillow@7.2.0
12.3.0

Open the chart page →

18,863
datacube-indexdatacube-charts0.4.41 of 2See more

datacube-index datacube-charts 0.4.4

1 of the 2 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0-1ubuntu1
pillow@10.2.0
no fix listed
12.3.0

Open the chart page →

6,123
datacube-owsdatacube-charts0.20.11 of 1See more

datacube-ows datacube-charts 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
opendatacube/ows:latest668cbb41473c
pillow@10.2.0-1ubuntu1
pillow@10.2.0
no fix listed
12.3.0

Open the chart page →

5,974
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
pillow@9.0.1-1ubuntu0.3
pillow@9.0.1
no fix listed
12.3.0

Open the chart page →

6,172
supersetdeliveryheroVerified publisher1.1.31 of 1See more

superset deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pillow@11.3.0
12.3.0

Open the chart page →

2,305
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
quay.io/ortelius/ms-sbom-export:main-v10.0.933-g2e222ef43bdaa51598
pillow@12.0.0
12.3.0

Open the chart page →

11,160
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
pillow@9.3.0
12.3.0

Open the chart page →

14,856
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
pillow@11.1.0
12.3.0

Open the chart page →

19,224
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
pillow@9.3.0
12.3.0

Open the chart page →

25,122
rommernail-romm1.0.11 of 1See more

romm ernail-romm 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
rommapp/romm:4.4.1b909e95d1aab
pillow@10.4.0
12.3.0

Open the chart page →

2,896
huntingfactlyVerified publisher0.4.141 of 1See more

hunting factly 0.4.14

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pillow@9.3.0
12.3.0

Open the chart page →

4,085
tandoorgabe565Verified publisher0.9.91 of 2See more

tandoor gabe565 0.9.9

1 of the 2 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/tandoorrecipes/recipes:1.5.31063eb446e298
pillow@10.4.0
12.3.0

Open the chart page →

2,183
babybuddygeek-cookbookVerified publisher1.2.21 of 1See more

babybuddy geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
linuxserver/babybuddy:1.10.2f7d7c7704249
pillow@9.0.1
12.3.0

Open the chart page →

1,489
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
12.3.0

Open the chart page →

1,150
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0-1ubuntu0.6
pillow@5.1.0
no fix listed
12.3.0

Open the chart page →

13,551
mylargeek-cookbookVerified publisher4.4.21 of 1See more

mylar geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
pillow@6.2.2
12.3.0

Open the chart page →

1,423
pyloadgeek-cookbookVerified publisher6.4.21 of 1See more

pyload geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/pyload:version-5de90278d3c87933a5fd
pillow@6.2.2
12.3.0

Open the chart page →

1,236
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pillow@8.3.1
12.3.0

Open the chart page →

24,293
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
pillow@12.0.0
12.3.0

Open the chart page →

8,923
esphomehelm-chart-roeiVerified publisher2025.3.01 of 1See more

esphome helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
esphome/esphome:2025.3.0def8b6e4f517
pillow@10.4.0
12.3.0

Open the chart page →

6,008
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
pillow@11.1.0
12.3.0

Open the chart page →

4,647
supersethelm-charts-nr1.1.31 of 1See more

superset helm-charts-nr 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
apache/superset:latest16b50bbef664
pillow@11.3.0
12.3.0

Open the chart page →

2,305
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
pillow@7.2.0
12.3.0

Open the chart page →

7,984
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
pillow@12.2.0
12.3.0

Open the chart page →

11,042
supersethelmforgeVerified publisher1.3.61 of 5See more

superset helmforge 1.3.6

1 of the 5 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
apache/superset:6.1.016b50bbef664
pillow@11.3.0
12.3.0

Open the chart page →

5,714
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
pillow@11.1.0
12.3.0

Open the chart page →

25,017
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
pillow@10.1.0
12.3.0

Open the chart page →

16,384
ilum-streamlitilumVerified publisher0.1.01 of 1See more

ilum-streamlit ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ilum/streamlit-example:1.0.0ce5dcdeb22ba
pillow@12.0.0
12.3.0

Open the chart page →

2,736
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
12.3.0

Open the chart page →

6,501
frigateimprowisedVerified publisher1.1.01 of 1See more

frigate improwised 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
pillow@10.2.0
12.3.0

Open the chart page →

2,159
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
pillow@11.1.0
12.3.0

Open the chart page →

5,062
label-studioinseefrlab2.3.11 of 3See more

label-studio inseefrlab 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
heartexlabs/label-studio:latestaa461572e8f9
pillow@12.1.1
12.3.0

Open the chart page →

3,157
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
pillow@11.0.0
12.3.0

Open the chart page →

17,852
inventreeinventreeOfficialVerified publisher0.4.281 of 2See more

inventree inventree 0.4.28

1 of the 2 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
pillow@11.1.0-5+deb13u4
pillow@11.1.0
no fix listed
12.3.0

Open the chart page →

5,788
twitch-channel-points-minerjacobcolvinVerified publisher0.1.01 of 1See more

twitch-channel-points-miner jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
pillow@10.0.0
12.3.0

Open the chart page →

1,088
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
pillow@9.4.0-1.1+deb12u1
pillow@9.4.0
no fix listed
12.3.0

Open the chart page →

10,780
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
pillow@12.2.0
12.3.0

Open the chart page →

5,040
bazarrk8s-home-lab-repo11.3.21 of 1See more

bazarr k8s-home-lab-repo 11.3.2

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
pillow@12.2.0
12.3.0

Open the chart page →

1,794
beetsk8s-home-lab-repo3.1.11 of 1See more

beets k8s-home-lab-repo 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
pillow@11.2.1
12.3.0

Open the chart page →

2,733
frigatek8s-home-lab-repo9.1.11 of 1See more

frigate k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@8.1.2
12.3.0

Open the chart page →

2,370
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
pillow@11.3.0
12.3.0

Open the chart page →

9,103
music-assistantkarljorgensen0.1.31 of 1See more

music-assistant karljorgensen 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
pillow@12.1.1
12.3.0

Open the chart page →

7,081
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
pillow@10.0.1
12.3.0

Open the chart page →

6,447
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
pillow@10.4.0
12.3.0

Open the chart page →

8,405
delugelinkding0.2.31 of 1See more

deluge linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
linuxserver/deluge:libtorrentv1-2.2.0-ls40052eac68ccc0
pillow@11.2.1
12.3.0

Open the chart page →

1,433
calendar-apiliturgical0.1.51 of 1See more

calendar-api liturgical 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
pillow@11.3.0
12.3.0

Open the chart page →

1,556
liturgical-apiliturgical0.2.111 of 1See more

liturgical-api liturgical 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
pillow@12.1.1
12.3.0

Open the chart page →

1,004
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
pillow@12.2.0
12.3.0

Open the chart page →

2,444
exposureloglsst-sqre0.2.11 of 1See more

exposurelog lsst-sqre 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
lsstsqre/exposurelog:0.8.079b00fb67a65
pillow@9.0.1
12.3.0

Open the chart page →

2,078
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-59205.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pillow@10.2.0
12.3.0

Open the chart page →

4,647

Container images carrying it

202 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
opea/speecht5:1.0249afad3d268
pillow@10.2.0
12.3.0
1
opea/tts:1.0257ae94709e9
pillow@10.2.0
12.3.0
1
opea/web-retriever-chroma:1.0fe08165d7770
pillow@10.4.0
12.3.0
1
openbas/caldera-server:5.1.0a277796d9724
pillow@11.1.0
12.3.0
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
pillow@11.2.1
12.3.0
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
pillow@12.1.0
12.3.0
1
opencsghq/csgship-web:v0.4.0c36a5bac3cf0
pillow@11.3.0
12.3.0
1
opencsghq/label-studio:v2.5.047e22aa71870
pillow@11.3.0
12.3.0
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
pillow@11.3.0
12.3.0
1
opendatacube/explorer:latest120457ffcd69
pillow@10.2.0-1ubuntu1
pillow@10.2.0
no fix listed
12.3.0
1
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0-1
pillow@5.1.0
no fix listed
12.3.0
1
opendatacube/wps:latest80df355a660b
pillow@9.0.1-1ubuntu0.3
pillow@9.0.1
no fix listed
12.3.0
1
openmined/syft-backend:0.9.5b72f74a68b32
pillow@11.1.0
12.3.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
pillow@10.2.0
12.3.0
1
prowlercloud/prowler-api:5.31.14f252d579be2
pillow@12.2.0
12.3.0
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
pillow@11.3.0
12.3.0
1
psono/psono-server:5.0.03b974b43ea03
pillow@10.3.0
12.3.0
1
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
pillow@10.0.0
12.3.0
1
robmarkcole/deepstack-ui:latest410275726459
pillow@8.3.2
12.3.0
1
rommapp/romm:4.4.1b909e95d1aab
pillow@10.4.0
12.3.0
1
saidsef/scapy-containerised:v2025.02f17f7c435891
pillow@11.1.0
12.3.0
1
scrapinghub/splash:3.4.1a5f89bc84606
pillow@5.4.1
12.3.0
1
seafileltd/seafile-mc:9.0.106693911bcc40
pillow@9.3.0
12.3.0
1
seafileltd/seafile-mc:10.0.170628f29c663
pillow@9.3.0
12.3.0
1
seafileltd/seafile-mc:9.0.97ac833196f60
pillow@9.2.0
12.3.0
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
pillow@10.2.0
12.3.0
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
pillow@8.3.1
12.3.0
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
pillow@10.4.0
12.3.0
1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
pillow@10.3.0
12.3.0
1
sruthitanneru/pi-sample:ui-lateste565ea454ffd
pillow@11.0.0
12.3.0
1
szurubooru/server:2.5accf2ad9fbc3
pillow@11.2.1
12.3.0
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pillow@9.4.0
12.3.0
1
taigaio/taiga-back:6.4.29f97323cc150
pillow@8.2.0
12.3.0
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pillow@11.1.0
12.3.0
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pillow@5.0.0
12.3.0
1
timothyclarke/wptserver:2018-03-0840a80ced8031
pillow@2.6.1
12.3.0
1
tombursch/kitchenowl-backend:v0.7.8b48e4ab727cd
pillow@12.2.0
12.3.0
1
vabene1111/recipes:2.3.50f8d061895e9
pillow@11.3.0
12.3.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
pillow@9.0.0
12.3.0
1
weblate/weblate:3.11.3-182848df56ecd
pillow@5.4.1
12.3.0
1
wger/server:2.6997ead43aabd
pillow@12.2.0
12.3.0
1
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pillow@8.4.0
12.3.0
1
zurdi15/romm:2.3.12db88fe44c89
pillow@10.1.0
12.3.0
1
gcr.io/getindata-images-public/mlflow:latest25d6975951f1
pillow@10.3.0
12.3.0
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
pillow@11.0.0
12.3.0
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
pillow@10.4.0
12.3.0
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
pillow@10.2.0
12.3.0
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pillow@8.1.2
12.3.0
1
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
pillow@11.0.0
12.3.0
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
pillow@10.2.0
12.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.