OSPulse

Is pillow healthy, maintained, and safe?

55/ 100
pillowv12.3.0
Medium riskconfidence: Highview on pypi.org

No — pillow carries 10 unpatched critical advisories and should not be adopted without a remediation plan.

vital-signs traceirregular · weakening

The verdict

OSPulse scores pillow at 55/100 (medium risk), computed deterministically from live PyPI release history, and the OSV vulnerability database. No — pillow carries 10 unpatched critical advisories and should not be adopted without a remediation plan.

Its most recent release shipped on 1 July 2026 — 27 days ago — so development is clearly active. Across 107 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. PyPI doesn't expose a reliable maintainer count, so bus-factor isn't scored here — treat maintenance depth as unknown rather than assumed.

OSV lists 153 known advisories for pillow, including 10 critical and 50 high. Open critical advisories are the strongest possible signal to pin to a patched version, replace, or fork before shipping. Each advisory is listed with its OSV/GHSA identifier below.

pillow is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own requirements.txt through the free health check, or have OSPulse monitor your whole dependency tree continuously.

Evidence trail — deterministic, auditable

Last release recency
27 days ago · active
Release cadence
steady · typical gap ~58d
Maintainer bus factor
not available from PyPI — not penalised
Known vulnerabilities (OSV)
153 advisories · 10 critical · 50 high
-45
Package age
16.0 years · 107 releases

Known vulnerabilities (153)

  • GHSA-3c5c-7235-994jHIGHCVE-2016-2533PYSEC-2016-19

    Pillow buffer overflow in ImagingPcdDecode

  • GHSA-3f63-hfp8-52jqCRITICALBIT-pillow-2023-50447CVE-2023-50447PYSEC-2026-457

    Arbitrary Code Execution in Pillow

  • GHSA-3wvg-mj6g-m9cvHIGHBIT-pillow-2021-27922CVE-2021-27922PYSEC-2021-41

    Pillow Uncontrolled Resource Consumption

  • GHSA-3xv8-3j54-hgrpHIGHBIT-pillow-2020-10378CVE-2020-10378PYSEC-2020-77

    Out-of-bounds read in Pillow

  • GHSA-43fq-w8qq-v88hCRITICALBIT-pillow-2020-11538CVE-2020-11538PYSEC-2020-80

    Out-of-bounds read in Pillow

  • GHSA-44wm-f244-xhp3HIGHBIT-pillow-2024-28219CVE-2024-28219PYSEC-2026-1793

    Pillow buffer overflow vulnerability

  • GHSA-45hq-cxwh-f6vcHIGHBIT-pillow-2026-55379CVE-2026-55379PYSEC-2026-2255

    Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

  • Infinite loop in Pillow

  • GHSA-4x4j-2g7c-83w6MODERATEBIT-pillow-2026-55798CVE-2026-55798PYSEC-2026-2257

    Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path

  • GHSA-57h3-9rgr-c24mCRITICALBIT-pillow-2021-25289CVE-2021-25289PYSEC-2021-35

    Out of bounds write in Pillow

  • GHSA-5gm3-px64-rw72HIGHCVE-2019-19911PYSEC-2020-172

    Uncontrolled Resource Consumption in Pillow

  • GHSA-5x94-69rx-g8h2HIGHBIT-pillow-2026-54060CVE-2026-54060PYSEC-2026-2254

    Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

  • GHSA-5xmw-vc9v-4wf2MODERATEBIT-pillow-2026-42309CVE-2026-42309PYSEC-2026-2251

    Pillow has a heap buffer overflow with nested list coordinates

  • GHSA-62p4-gmf7-7g93HIGHBIT-pillow-2026-54058CVE-2026-54058PYSEC-2026-3493

    Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

  • GHSA-6r8x-57c9-28j4HIGHBIT-pillow-2026-59199CVE-2026-59199PYSEC-2026-3451

    Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

  • GHSA-7534-mm45-c74vCRITICALBIT-pillow-2021-34552CVE-2021-34552PYSEC-2021-331

    Buffer Overflow in Pillow

  • GHSA-77gc-v2xv-rvvhHIGHBIT-pillow-2021-25287CVE-2021-25287PYSEC-2021-137

    Out-of-bounds Read in Pillow

  • GHSA-7r7m-5h27-29hpHIGHBIT-pillow-2021-28676CVE-2021-28676PYSEC-2021-92

    Potential infinite loop in Pillow

  • GHSA-8843-m7mw-mxqmHIGHBIT-pillow-2020-10379CVE-2020-10379PYSEC-2020-78

    Buffer overflow in Pillow

  • GHSA-8ghj-p4vj-mr35HIGHBIT-pillow-2023-44271CVE-2023-44271PYSEC-2023-227

    Pillow Denial of Service vulnerability

  • GHSA-8m9x-pxwq-j236CRITICALCVE-2014-3007PYSEC-2014-87

    Pillow command injection

  • GHSA-8v84-f9pq-wr9xHIGHBIT-pillow-2026-54059CVE-2026-54059PYSEC-2026-2253

    Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

  • GHSA-8vj2-vxx3-667wCRITICALBIT-pillow-2022-22817CVE-2022-22817PYSEC-2022-10

    Arbitrary expression injection in Pillow

  • GHSA-8xjq-8fcg-g5hwHIGHBIT-pillow-2021-25290CVE-2021-25290PYSEC-2021-36

    Out-of-bounds Write in Pillow

  • GHSA-8xjv-v9xq-m5h9HIGHCVE-2016-0775PYSEC-2016-6

    Pillow Buffer overflow in ImagingFliDecode

  • GHSA-95q3-8gr9-gm8wHIGHBIT-pillow-2021-27923CVE-2021-27923PYSEC-2021-42

    Pillow Denial of Service by Uncontrolled Resource Consumption

  • GHSA-98vv-pw6r-q6q4HIGHBIT-pillow-2021-23437CVE-2021-23437PYSEC-2021-317

    Uncontrolled Resource Consumption in pillow

  • GHSA-9hw9-ch79-4vh6HIGHBIT-pillow-2026-59205CVE-2026-59205PYSEC-2026-3453

    Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch

  • GHSA-9hx2-hgq2-2g4fMODERATEBIT-pillow-2021-25292CVE-2021-25292PYSEC-2021-38

    Regular Expression Denial of Service (ReDoS) in Pillow

  • GHSA-9j59-75qj-795wHIGHBIT-pillow-2022-24303CVE-2022-24303PYSEC-2022-168

    Path traversal in Pillow

  • GHSA-cfh3-3jmp-rvhcHIGHBIT-pillow-2026-25990CVE-2026-25990PYSEC-2026-2249

    Pillow affected by out-of-bounds write when loading PSD images

  • GHSA-cfmr-38g9-f2h7HIGHCVE-2014-3589PYSEC-2014-10

    Pillow denial of service via Crafted Block Size

  • GHSA-cqhg-xjhh-p8hfHIGHBIT-pillow-2020-10177CVE-2020-10177PYSEC-2020-76

    Out-of-bounds reads in Pillow

  • GHSA-f4w8-cv6p-x6r5HIGHBIT-pillow-2021-27921CVE-2021-27921PYSEC-2021-40

    Pillow Denial of Service by Uncontrolled Resource Consumption

  • GHSA-f5g8-5qq7-938wHIGHBIT-pillow-2020-35653CVE-2020-35653PYSEC-2021-69

    Pillow Out-of-bounds Read

  • GHSA-fj7v-r99m-22gqMODERATEBIT-pillow-2026-59198CVE-2026-59198PYSEC-2026-3494

    Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

  • GHSA-g6rj-rv7j-xwp4HIGHBIT-pillow-2021-28675CVE-2021-28675PYSEC-2021-139

    Pillow denial of service

  • GHSA-h5rf-vgqx-wjv2HIGHCVE-2014-9601PYSEC-2015-16

    Pillow denial of service via PNG bomb

  • GHSA-hf64-x4gq-p99hMODERATEBIT-pillow-2020-35655CVE-2020-35655PYSEC-2021-71

    Pillow Out-of-bounds Read

  • GHSA-hggx-3h72-49wwMODERATECVE-2016-0740PYSEC-2016-5

    Pillow Buffer overflow in ImagingLibTiffDecode

  • GHSA-hj69-c76v-86wrHIGHBIT-pillow-2020-5313CVE-2020-5313PYSEC-2020-84

    Out-of-bounds Read in Pillow

  • GHSA-hjfx-8p6c-g7gxMODERATEBIT-pillow-2021-28678CVE-2021-28678PYSEC-2021-94

    Insufficient Verification of Data Authenticity in Pillow

  • GHSA-hr8g-f6r6-mr22HIGHBIT-pillow-2022-30595CVE-2022-30595PYSEC-2022-43145

    Buffer over-flow in Pillow

  • GHSA-hvr8-466p-75rhCRITICALCVE-2016-4009PYSEC-2016-7

    Pillow Integer overflow in ImagingResampleHorizontal

  • GHSA-j6f7-g425-4gmxHIGHCVE-2014-3598PYSEC-2015-15

    Pillow is vulnerable to Denial of Service (DOS) in the Jpeg2KImagePlugin

  • GHSA-j7hp-h8jx-5pprHIGHA-299477569ASB-A-299477569CVE-2023-4863

    libwebp: OOB write in BuildHuffmanTable

  • GHSA-j7mj-748x-7p78HIGHCVE-2019-16865PYSEC-2019-110

    DOS attack in Pillow when processing specially crafted image files

  • Uncontrolled Resource Consumption in pillow

  • GHSA-jjj6-mw9f-p565HIGHBIT-pillow-2026-59200CVE-2026-59200PYSEC-2026-3495

    Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

  • GHSA-m2vv-5vj5-2hm7HIGHBIT-pillow-2022-45198CVE-2022-45198PYSEC-2022-42979

    Pillow vulnerable to Data Amplification attack.

  • GHSA-mvg9-xffr-p774HIGHBIT-pillow-2021-25291CVE-2021-25291PYSEC-2021-37

    Out of bounds read in Pillow

  • GHSA-p43w-g3c5-g5mqHIGHBIT-pillow-2021-25293CVE-2021-25293PYSEC-2021-39

    Out of bounds read in Pillow

  • GHSA-p49h-hjvm-jg3hCRITICALBIT-pillow-2020-5312CVE-2020-5312PYSEC-2020-83

    PCX P mode buffer overflow in Pillow

  • GHSA-pg7v-jwj7-p798MODERATEBIT-pillow-2026-59203CVE-2026-59203PYSEC-2026-3452

    Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service

  • GHSA-phj9-mv4w-65pmHIGHBIT-pillow-2026-55380CVE-2026-55380PYSEC-2026-2256

    Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`

  • GHSA-pw3c-h7wp-cvhxMODERATEBIT-pillow-2022-22815CVE-2022-22815PYSEC-2022-8

    Improper Initialization in Pillow

  • GHSA-pwv6-vv43-88grHIGHBIT-pillow-2026-42311CVE-2026-42311PYSEC-2026-2252

    Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)

  • GHSA-q4mp-jvh2-76fjHIGHBIT-pillow-2022-45199CVE-2022-45199PYSEC-2022-42980

    Pillow subject to DoS via SAMPLESPERPIXEL tag

  • GHSA-q5hq-fp76-qmrcHIGHBIT-pillow-2021-28677CVE-2021-28677PYSEC-2021-93

    Uncontrolled Resource Consumption in Pillow

  • GHSA-r73j-pqj5-w3x7MODERATEBIT-pillow-2026-42310CVE-2026-42310PYSEC-2026-2874

    Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

  • GHSA-r7rm-8j6h-r933CRITICALBIT-pillow-2020-5311CVE-2020-5311PYSEC-2020-82

    Buffer Copy without Checking Size of Input in Pillow

  • GHSA-r854-96gq-rfg3MODERATECVE-2014-1933PYSEC-2014-23

    Pillow Temporary file name leakage

  • GHSA-rwr3-c2q8-gm56MODERATECVE-2016-9189PYSEC-2016-8

    Pillow Integer overflow in Map.c

  • GHSA-rwv7-3v45-hg29HIGHBIT-pillow-2021-25288CVE-2021-25288PYSEC-2021-138

    Pillow Out-of-bounds Read vulnerability

  • GHSA-v9pc-9mvp-x87gHIGHCVE-2016-3076PYSEC-2017-92

    Pillow Buffer overflow in Jpeg2KEncode.c

  • GHSA-vcqg-3p29-xw73CRITICALBIT-pillow-2020-5310CVE-2020-5310PYSEC-2020-81

    Integer overflow in Pillow

  • GHSA-vj42-xq3r-hr3rHIGHBIT-pillow-2020-10994CVE-2020-10994PYSEC-2020-79

    Out-of-bounds reads in Pillow

  • GHSA-vjc4-5qp5-m44jHIGHBIT-pillow-2026-59204CVE-2026-59204PYSEC-2026-3496

    Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

  • GHSA-vqcj-wrf2-7v73HIGHBIT-pillow-2020-35654CVE-2020-35654PYSEC-2021-70

    Pillow Out-of-bounds Write

  • GHSA-w4vg-rf63-f3j3HIGHCVE-2016-9190PYSEC-2016-9

    Arbitrary code using "crafted image file" approach affecting Pillow

  • GHSA-whj4-6x5x-4v2jHIGHBIT-pillow-2026-40192CVE-2026-40192PYSEC-2026-2250

    FITS GZIP decompression bomb in Pillow

  • GHSA-wjx4-4jcj-g98jMODERATEBIT-pillow-2026-42308CVE-2026-42308PYSEC-2026-165

    Pillow has an integer overflow when processing fonts

  • GHSA-x895-2wrm-hvp7HIGHCVE-2014-1932PYSEC-2014-22

    PIL and Pillow Vulnerable to Symlink Attack on Tmpfiles

  • GHSA-xg8h-j46f-w952HIGHBIT-pillow-2025-48379CVE-2025-48379PYSEC-2025-61

    Pillow vulnerability can cause write buffer overflow on BCn encoding

  • GHSA-xj96-63gp-2gmrHIGHBIT-pillow-2026-59197CVE-2026-59197PYSEC-2026-3454

    Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

  • GHSA-xrcv-f9gm-v42cMODERATEBIT-pillow-2022-22816CVE-2022-22816PYSEC-2022-9

    Out-of-bounds Read in Pillow

  • Invalid-free in _dealloc

  • Segv on unknown address in jpeg_read_scanlines

  • PYSEC-2014-10UNKNOWNCVE-2014-3589GHSA-cfmr-38g9-f2h7

    PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.

  • PYSEC-2014-22UNKNOWNCVE-2014-1932GHSA-x895-2wrm-hvp7

    The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (P

  • PYSEC-2014-23UNKNOWNCVE-2014-1933GHSA-r854-96gq-rfg3

    The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes

  • PYSEC-2014-87UNKNOWNCVE-2014-3007GHSA-8m9x-pxwq-j236

    Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibl

  • PYSEC-2015-15UNKNOWNCVE-2014-3598GHSA-j6f7-g425-4gmx

    The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.

  • PYSEC-2015-16UNKNOWNCVE-2014-9601GHSA-h5rf-vgqx-wjv2

    Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

  • PYSEC-2016-19UNKNOWNCVE-2016-2533GHSA-3c5c-7235-994j

    Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) v

  • PYSEC-2016-5UNKNOWNCVE-2016-0740GHSA-hggx-3h72-49ww

    Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.

  • PYSEC-2016-6UNKNOWNCVE-2016-0775GHSA-8xjv-v9xq-m5h9

    Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.

  • PYSEC-2016-7UNKNOWNCVE-2016-4009GHSA-hvr8-466p-75rh

    Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which

  • PYSEC-2016-8UNKNOWNCVE-2016-9189GHSA-rwr3-c2q8-gm56

    Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_b

  • PYSEC-2016-9UNKNOWNCVE-2016-9190GHSA-w4vg-rf63-f3j3

    Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in S

  • PYSEC-2017-92UNKNOWNCVE-2016-3076GHSA-v9pc-9mvp-x87g

    Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.

  • PYSEC-2019-110UNKNOWNCVE-2019-16865GHSA-j7mj-748x-7p78

    An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of tim

  • PYSEC-2020-172UNKNOWNCVE-2019-19911GHSA-5gm3-px64-rw72

    There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit P

  • PYSEC-2020-76UNKNOWNBIT-pillow-2020-10177CVE-2020-10177GHSA-cqhg-xjhh-p8hf

    Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.

  • PYSEC-2020-77UNKNOWNBIT-pillow-2020-10378CVE-2020-10378GHSA-3xv8-3j54-hgrp

    In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.

  • PYSEC-2020-78UNKNOWNBIT-pillow-2020-10379CVE-2020-10379GHSA-8843-m7mw-mxqm

    In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.

  • PYSEC-2020-79UNKNOWNBIT-pillow-2020-10994CVE-2020-10994GHSA-vj42-xq3r-hr3r

    In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.

  • PYSEC-2020-80UNKNOWNBIT-pillow-2020-11538CVE-2020-11538GHSA-43fq-w8qq-v88h

    In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.

  • PYSEC-2020-81UNKNOWNBIT-pillow-2020-5310CVE-2020-5310GHSA-vcqg-3p29-xw73

    libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.

  • PYSEC-2020-82UNKNOWNBIT-pillow-2020-5311CVE-2020-5311GHSA-r7rm-8j6h-r933

    libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.

  • PYSEC-2020-83UNKNOWNBIT-pillow-2020-5312CVE-2020-5312GHSA-p49h-hjvm-jg3h

    libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.

  • PYSEC-2020-84UNKNOWNBIT-pillow-2020-5313CVE-2020-5313GHSA-hj69-c76v-86wr

    libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.

  • PYSEC-2021-137UNKNOWNBIT-pillow-2021-25287CVE-2021-25287GHSA-77gc-v2xv-rvvh

    An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.

  • PYSEC-2021-138UNKNOWNBIT-pillow-2021-25288CVE-2021-25288GHSA-rwv7-3v45-hg29

    An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.

  • PYSEC-2021-139UNKNOWNBIT-pillow-2021-28675CVE-2021-28675GHSA-g6rj-rv7j-xwp4

    An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input layers relative to the size of the data block. This could lead to a DoS on Imag

  • PYSEC-2021-317UNKNOWNBIT-pillow-2021-23437CVE-2021-23437GHSA-98vv-pw6r-q6q4

    The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

  • PYSEC-2021-331UNKNOWNBIT-pillow-2021-34552CVE-2021-34552GHSA-7534-mm45-c74v

    Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.

  • PYSEC-2021-35UNKNOWNBIT-pillow-2021-25289CVE-2021-25289GHSA-57h3-9rgr-c24m

    An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. NOT

  • PYSEC-2021-36UNKNOWNBIT-pillow-2021-25290CVE-2021-25290GHSA-8xjq-8fcg-g5hw

    An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.

  • PYSEC-2021-37UNKNOWNBIT-pillow-2021-25291CVE-2021-25291GHSA-mvg9-xffr-p774

    An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via invalid tile boundaries.

  • PYSEC-2021-38UNKNOWNBIT-pillow-2021-25292CVE-2021-25292GHSA-9hx2-hgq2-2g4f

    An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a crafted PDF file because of a catastrophic backtracking regex.

  • PYSEC-2021-39UNKNOWNBIT-pillow-2021-25293CVE-2021-25293GHSA-p43w-g3c5-g5mq

    An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.

  • PYSEC-2021-40UNKNOWNBIT-pillow-2021-27921CVE-2021-27921GHSA-f4w8-cv6p-x6r5

    Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted

  • PYSEC-2021-41UNKNOWNBIT-pillow-2021-27922CVE-2021-27922GHSA-3wvg-mj6g-m9cv

    Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempt

  • PYSEC-2021-42UNKNOWNBIT-pillow-2021-27923CVE-2021-27923GHSA-95q3-8gr9-gm8w

    Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempte

  • PYSEC-2021-69UNKNOWNBIT-pillow-2020-35653CVE-2020-35653GHSA-f5g8-5qq7-938w

    In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations.

  • PYSEC-2021-70UNKNOWNBIT-pillow-2020-35654CVE-2020-35654GHSA-vqcj-wrf2-7v73

    In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.

  • PYSEC-2021-71UNKNOWNBIT-pillow-2020-35655CVE-2020-35655GHSA-hf64-x4gq-p99h

    In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.

  • PYSEC-2021-92UNKNOWNBIT-pillow-2021-28676CVE-2021-28676GHSA-7r7m-5h27-29hp

    An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.

  • PYSEC-2021-93UNKNOWNBIT-pillow-2021-28677CVE-2021-28677GHSA-q5hq-fp76-qmrc

    An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally qu

  • PYSEC-2021-94UNKNOWNBIT-pillow-2021-28678CVE-2021-28678GHSA-hjfx-8p6c-g7gx

    An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after jumping to file offsets) returned data. This could lead to a DoS where the decoder

  • PYSEC-2022-10UNKNOWNBIT-pillow-2022-22817CVE-2022-22817GHSA-8vj2-vxx3-667w

    PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method.

  • PYSEC-2022-168UNKNOWNBIT-pillow-2022-24303CVE-2022-24303GHSA-9j59-75qj-795w

    Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

  • PYSEC-2022-42979UNKNOWNBIT-pillow-2022-45198CVE-2022-45198GHSA-m2vv-5vj5-2hm7

    Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).

  • PYSEC-2022-42980UNKNOWNBIT-pillow-2022-45199CVE-2022-45199GHSA-q4mp-jvh2-76fj

    Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.

  • PYSEC-2022-43145LOWBIT-pillow-2022-30595CVE-2022-30595GHSA-hr8g-f6r6-mr22

    libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.

  • PYSEC-2022-8UNKNOWNBIT-pillow-2022-22815CVE-2022-22815GHSA-pw3c-h7wp-cvhx

    path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.

  • PYSEC-2022-9UNKNOWNBIT-pillow-2022-22816CVE-2022-22816GHSA-xrcv-f9gm-v42c

    path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

  • Pillow versions before v10.0.1 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). Pillow v10.0.1 upgrades the bundled libwebp binary to v1.3.2.

  • PYSEC-2023-227UNKNOWNBIT-pillow-2023-44271CVE-2023-44271GHSA-8ghj-p4vj-mr35

    An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of

  • PYSEC-2025-61UNKNOWNBIT-pillow-2025-48379CVE-2025-48379GHSA-xg8h-j46f-w952

    Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format

  • PYSEC-2026-165LOWBIT-pillow-2026-42308CVE-2026-42308GHSA-wjx4-4jcj-g98j

    Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer

  • PYSEC-2026-1793LOWBIT-pillow-2024-28219CVE-2024-28219GHSA-44wm-f244-xhp3

    Pillow buffer overflow vulnerability

  • PYSEC-2026-1794LOWA-299477569ASB-A-299477569CVE-2023-4863

    libwebp: OOB write in BuildHuffmanTable

  • PYSEC-2026-2249LOWBIT-pillow-2026-25990CVE-2026-25990GHSA-cfh3-3jmp-rvhc

    Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

  • PYSEC-2026-2250LOWBIT-pillow-2026-40192CVE-2026-40192GHSA-whj4-6x5x-4v2j

    Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attack

  • PYSEC-2026-2251LOWBIT-pillow-2026-42309CVE-2026-42309GHSA-5xmw-vc9v-4wf2

    Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygo

  • PYSEC-2026-2252LOWBIT-pillow-2026-42311CVE-2026-42311GHSA-pwv6-vv43-88gr

    Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code ex

  • PYSEC-2026-2253LOWBIT-pillow-2026-54059CVE-2026-54059GHSA-8v84-f9pq-wr9x

    Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling

  • PYSEC-2026-2254LOWBIT-pillow-2026-54060CVE-2026-54060GHSA-5x94-69rx-g8h2

    Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._dec

  • PYSEC-2026-2255LOWBIT-pillow-2026-55379CVE-2026-55379GHSA-45hq-cxwh-f6vc

    Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() wit

  • PYSEC-2026-2256LOWBIT-pillow-2026-55380CVE-2026-55380GHSA-phj9-mv4w-65pm

    Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompress

  • PYSEC-2026-2257LOWBIT-pillow-2026-55798CVE-2026-55798GHSA-4x4j-2g7c-83w6

    Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the

  • PYSEC-2026-2874LOWBIT-pillow-2026-42310CVE-2026-42310GHSA-r73j-pqj5-w3x7

    Pillow has a PDF Parsing Trailer Infinite Loop (DoS)

  • PYSEC-2026-3451LOWBIT-pillow-2026-59199CVE-2026-59199GHSA-6r8x-57c9-28j4

    Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in I

  • PYSEC-2026-3452LOWBIT-pillow-2026-59203CVE-2026-59203GHSA-pg7v-jwj7-p798

    Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file t

  • PYSEC-2026-3453LOWBIT-pillow-2026-59205CVE-2026-59205GHSA-9hw9-ch79-4vh6

    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image who

  • PYSEC-2026-3454LOWBIT-pillow-2026-59197CVE-2026-59197GHSA-xj96-63gp-2gmr

    Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilte

  • PYSEC-2026-3493MEDIUMBIT-pillow-2026-54058CVE-2026-54058GHSA-62p4-gmf7-7g93

    Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)

  • PYSEC-2026-3494LOWBIT-pillow-2026-59198CVE-2026-59198GHSA-fj7v-r99m-22gq

    Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

  • PYSEC-2026-3495LOWBIT-pillow-2026-59200CVE-2026-59200GHSA-jjj6-mw9f-p565

    Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

  • PYSEC-2026-3496MEDIUMBIT-pillow-2026-59204CVE-2026-59204GHSA-vjc4-5qp5-m44j

    Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

  • PYSEC-2026-457LOWBIT-pillow-2023-50447CVE-2023-50447GHSA-3f63-hfp8-52jq

    Arbitrary Code Execution in Pillow

Key facts

Latest version
v12.3.0
Last release
1 July 2026 (27 days ago)
Total releases
107
First release
31 July 2010
Package age
16.0 years
Maintainers
not exposed by PyPI
Known advisories
153
Confidence
High

Frequently asked

Is pillow still maintained?

Yes — pillow released as recently as 1 July 2026 (27 days ago), so it is actively maintained.

Does pillow have known security vulnerabilities?

Yes — OSV lists 153 advisories for pillow, including 10 rated critical. See the advisory list on this page for the OSV/GHSA identifiers.

Is pillow safe to use?

No — pillow carries 10 unpatched critical advisories and should not be adopted without a remediation plan. OSPulse rates it 55/100 (medium risk) based on release recency, cadence and known vulnerabilities.

Other PyPI packages we've checked

Browse all checked packages →

pillow is one package. What about the other hundreds in your tree?

Paste your own requirements.txt into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.

Data from the PyPI registry & OSV.dev · snapshot generated 2026-07-28 · scores are deterministic and recomputed on each refresh.