CVE-2021-23437

HIGH

Python Pillow < 8.3.2 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

Scores

CVSS v3 7.5
EPSS 0.0023
EPSS Percentile 45.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (4)
fedoraproject/fedora 33
fedoraproject/fedora 34
pypi/pillow 5.2.0 - 8.3.2PyPI
python/pillow 5.2.0 - 8.3.2
Published Sep 03, 2021
Tracked Since Feb 18, 2026