CVE-2026-59205
HIGHPillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch
Title source: cnaDescription
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6
X_Refsource_Misc x_refsource_misc
https://github.com/python-pillow/Pillow/pull/9715
X_Refsource_Misc x_refsource_misc
https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721
X_Refsource_Misc x_refsource_misc
https://github.com/python-pillow/Pillow/releases/tag/12.3.0
Scores
CVSS v3
7.5
EPSS
0.0039
EPSS Percentile
31.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-787
Status
published
Products (3)
pypi/pillow
0 - 12.3.0PyPI
python/pillow
< 12.3.0
python-pillow/Pillow
< 12.3.0
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026