CVE-2026-54058
HIGHPillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
Title source: cnaDescription
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93
X_Refsource_Misc x_refsource_misc
https://github.com/python-pillow/Pillow/pull/9719
X_Refsource_Misc x_refsource_misc
https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90b3cfc1d
X_Refsource_Misc x_refsource_misc
https://github.com/python-pillow/Pillow/releases/tag/12.3.0
Scores
CVSS v4
8.3
EPSS
0.0038
EPSS Percentile
31.2%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-125
Status
published
Products (2)
pypi/pillow
0 - 12.3.0PyPI
python-pillow/Pillow
< 12.3.0
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026