Is pillow healthy, maintained, and safe?
No — pillow carries 10 unpatched critical advisories and should not be adopted without a remediation plan.
The verdict
OSPulse scores pillow at 55/100 (medium risk), computed deterministically from live PyPI release history, and the OSV vulnerability database. No — pillow carries 10 unpatched critical advisories and should not be adopted without a remediation plan.
Its most recent release shipped on 1 July 2026 — 27 days ago — so development is clearly active. Across 107 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.
OSV lists 153 known advisories for pillow, including 10 critical and 50 high. Open critical advisories are the strongest possible signal to pin to a patched version, replace, or fork before shipping. Each advisory is listed with its OSV/GHSA identifier below.
pillow is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (153)
Pillow buffer overflow in ImagingPcdDecode
Arbitrary Code Execution in Pillow
Pillow Uncontrolled Resource Consumption
Out-of-bounds read in Pillow
Out-of-bounds read in Pillow
Pillow buffer overflow vulnerability
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
Infinite loop in Pillow
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
Out of bounds write in Pillow
Uncontrolled Resource Consumption in Pillow
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
Pillow has a heap buffer overflow with nested list coordinates
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
Buffer Overflow in Pillow
Out-of-bounds Read in Pillow
Potential infinite loop in Pillow
Buffer overflow in Pillow
Pillow Denial of Service vulnerability
Pillow command injection
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
Arbitrary expression injection in Pillow
Out-of-bounds Write in Pillow
Pillow Buffer overflow in ImagingFliDecode
Pillow Denial of Service by Uncontrolled Resource Consumption
Uncontrolled Resource Consumption in pillow
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
Regular Expression Denial of Service (ReDoS) in Pillow
Path traversal in Pillow
Pillow affected by out-of-bounds write when loading PSD images
Pillow denial of service via Crafted Block Size
Out-of-bounds reads in Pillow
Pillow Denial of Service by Uncontrolled Resource Consumption
Pillow Out-of-bounds Read
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Pillow denial of service
Pillow denial of service via PNG bomb
Pillow Out-of-bounds Read
Pillow Buffer overflow in ImagingLibTiffDecode
Out-of-bounds Read in Pillow
Insufficient Verification of Data Authenticity in Pillow
Buffer over-flow in Pillow
Pillow Integer overflow in ImagingResampleHorizontal
Pillow is vulnerable to Denial of Service (DOS) in the Jpeg2KImagePlugin
libwebp: OOB write in BuildHuffmanTable
DOS attack in Pillow when processing specially crafted image files
- GHSA-jgpv-4h4c-xhw3 ↗MODERATE
Uncontrolled Resource Consumption in pillow
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
Pillow vulnerable to Data Amplification attack.
Out of bounds read in Pillow
Out of bounds read in Pillow
PCX P mode buffer overflow in Pillow
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
Improper Initialization in Pillow
Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
Pillow subject to DoS via SAMPLESPERPIXEL tag
Uncontrolled Resource Consumption in Pillow
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
Buffer Copy without Checking Size of Input in Pillow
Pillow Temporary file name leakage
Pillow Integer overflow in Map.c
Pillow Out-of-bounds Read vulnerability
Pillow Buffer overflow in Jpeg2KEncode.c
Integer overflow in Pillow
Out-of-bounds reads in Pillow
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
Pillow Out-of-bounds Write
Arbitrary code using "crafted image file" approach affecting Pillow
FITS GZIP decompression bomb in Pillow
Pillow has an integer overflow when processing fonts
PIL and Pillow Vulnerable to Symlink Attack on Tmpfiles
Pillow vulnerability can cause write buffer overflow on BCn encoding
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
Out-of-bounds Read in Pillow
- OSV-2022-1074 ↗UNKNOWN
Invalid-free in _dealloc
- OSV-2022-715 ↗UNKNOWN
Segv on unknown address in jpeg_read_scanlines
PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (P
The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes
Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibl
The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) v
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.
Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which
Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_b
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in S
Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of tim
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit P
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.
An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input layers relative to the size of the data block. This could lead to a DoS on Imag
The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOT
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.
An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.
An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempt
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempte
In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.
In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.
An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally qu
An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method.
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.
- PYSEC-2023-175 ↗UNKNOWN
Pillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). Pillow v10.0.1 upgrades the bundled libwebp binary to v1.3.2.
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of
Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer
Pillow buffer overflow vulnerability
libwebp: OOB write in BuildHuffmanTable
Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attack
Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygo
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code ex
Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling
Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._dec
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() wit
Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompress
Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in I
Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file t
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image who
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilte
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
Arbitrary Code Execution in Pillow
Key facts
- Latest version
- v12.3.0
- Last release
- 1 July 2026 (27 days ago)
- Total releases
- 107
- First release
- 31 July 2010
- Package age
- 16.0 years
- Maintainers
- not exposed by PyPI
- Known advisories
- 153
- Confidence
- High
Frequently asked
Is pillow still maintained?
Yes — pillow released as recently as 1 July 2026 (27 days ago), so it is actively maintained.
Does pillow have known security vulnerabilities?
Yes — OSV lists 153 advisories for pillow, including 10 rated critical. See the advisory list on this page for the OSV/GHSA identifiers.
Is pillow safe to use?
No — pillow carries 10 unpatched critical advisories and should not be adopted without a remediation plan. OSPulse rates it 55/100 (medium risk) based on release recency, cadence and known vulnerabilities.
Other PyPI packages we've checked
pillow is one package. What about the other hundreds in your tree?
Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the PyPI registry & OSV.dev · snapshot generated 2026-07-28 · scores are deterministic and recomputed on each refresh.
