Logo
vulnerabilityCVE-2026-42309
Name
CVE-2026-42309
Source
NVD ( link)Debian ( link)
Description
Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This issue has been patched in version 12.2.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python-pillow
Exploitable

Vulnerability Ratings#


5.1
CVSSv4
5.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
11.1.0
Not Affected
openwrt
master
12.2.0-r1
Not Affected
openwrt
openwrt-25.12
12.1.1-r1
Exploitable
yocto
kirkstone
9.4.0
Not Affected
yocto
master
12.2.0
Not Affected
yocto
scarthgap
10.3.0
Not Affected