CVE-2021-23437

HIGH

Pillow 5.2.0-8.3.1 - Regular Expression Denial of Service via getrgb Function

Title source: llm
STIX 2.1

Description

The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

Scores

CVSS v3 7.5
EPSS 0.0288
EPSS Percentile 85.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (4)
fedoraproject/fedora 33
fedoraproject/fedora 34
pypi/pillow 5.2.0 - 8.3.2PyPI
python/pillow 5.2.0 - 8.3.2
Published Sep 03, 2021
Tracked Since Feb 18, 2026