Vulnerability Description
Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Python | Pillow | >= 8.2.0, < 12.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea6Patch
- https://github.com/python-pillow/Pillow/pull/9704ExploitIssue TrackingPatch
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0Release Notes
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44jExploitVendor Advisory
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44jExploitVendor Advisory
FAQ
What is CVE-2026-59204?
CVE-2026-59204 is a vulnerability with a CVSS score of 7.5 (HIGH). Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile,...
How severe is CVE-2026-59204?
CVE-2026-59204 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-59204?
Check the references section above for vendor advisories and patch information. Affected products include: Python Pillow.