Logo
vulnerabilityCVE-2026-59205
Name
CVE-2026-59205
Source
NVD ( link)Debian ( link)
Description
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-pillow
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
11.1.0
Exploitable
buildroot
master
12.0.0
Exploitable
openwrt
master
12.2.0-r2
Exploitable
openwrt
openwrt-25.12
12.1.1-r1
Exploitable
yocto
kirkstone
9.4.0
Exploitable
yocto
master
12.3.0
Not Affected