CVE-2026-42309
published 2026-05-09CVE-2026-42309: Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
3.1th percentile
Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This issue has been patched in version 12.2.0.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-25 | lightspeed-chatbot-rhel8 | — | — |
| ansible-automation-platform-26 | hub-rhel9 | — | — |
| ansible-automation-platform-26 | lightspeed-chatbot-rhel9 | — | — |
| ansible-automation-platform | automation-dashboard-rhel9 | — | — |
| exploit-intelligence-tech-preview | vulnerability-analysis-rhel9 | — | — |
| openshift-lightspeed | lightspeed-ocp-rag-rhel9 | — | — |
| openshift-lightspeed | lightspeed-service-api-rhel9 | — | — |
| pen-drive | pen-drive-scanner-rhel9 | — | — |
| python-pillow | pillow | — | — |
| python | pillow | >= 11.2.1 < 12.2.0 | 12.2.0 |
| python | pillow | >= 11.2.1 < 12.2.0 | 12.2.0 |
| quay | quay-rhel8 | — | — |
| quay | quay-rhel9 | — | — |
| rhaiis | model-opt-cuda-rhel9 | — | — |
| rhaiis | vllm-cpu-rhel9 | — | — |
| rhaiis | vllm-cuda-rhel9 | — | — |
| rhaiis | vllm-neuron-rhel9 | — | — |
| rhaiis | vllm-rocm-rhel9 | — | — |
| rhaiis | vllm-spyre-rhel9 | — | — |
| rhaiis | vllm-tpu-rhel9 | — | — |
| rhelai3 | bootc-aws-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-rocm-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gcp-cuda-rhel9 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.05.1MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_ubuntu5.5MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Pillow up to 12.1.x heap-based overflow (GHSA-5xmw-vc9v-4wf2 / EUVD-2026-28901)
vuldb·2026-05-09·CVSS 5.1
CVE-2026-42309 [MEDIUM] Pillow up to 12.1.x heap-based overflow (GHSA-5xmw-vc9v-4wf2 / EUVD-2026-28901)
A vulnerability was found in Pillow up to 12.1.x. It has been classified as critical. The affected element is an unknown function. The manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2026-42309. The attack must be carried out locally. There is no available exploit.
Upgrading the affected component is recommended.
GHSA
Pillow has a heap buffer overflow with nested list coordinates
ghsa·2026-05-04
CVE-2026-42309 [MEDIUM] CWE-122 Pillow has a heap buffer overflow with nested list coordinates
Pillow has a heap buffer overflow with nested list coordinates
Passing nested lists as coordinates to APIs that accept coordinates such as `ImagePath.Path`, `ImageDraw.ImageDraw.polygon` and `ImageDraw.ImageDraw.line` could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This was introduced in Pillow 11.2.1.
Ubuntu
Pillow vulnerabilities
vendor_ubuntu·2026-06-08·CVSS 5.5
CVE-2026-42310 [MEDIUM] Pillow vulnerabilities
Title: Pillow vulnerabilities
Summary: Several security issues were fixed in Pillow.
It was discovered that Pillow incorrectly handled large glyph advance
values in fonts. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. (CVE-2026-42308)
It was discovered that Pillow incorrectly handled nested coordinate lists
in certain APIs. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. This issue only affected Ubuntu
25.10 and Ubuntu 26.04 LTS. (CVE-2026-42309)
It was discovered that Pillow incorrectly handled certain malformed PDF
files. An attacker could possibly use this issue to cause Pillow to use
excessive resources, leading to a denial of service. (CVE-2026-42310)
It was discovered th
Red Hat
Pillow: Pillow: Denial of Service via specially crafted coordinate input
vendor_redhat·2026-05-09·CVSS 5.1
CVE-2026-42309 [MEDIUM] CWE-131 Pillow: Pillow: Denial of Service via specially crafted coordinate input
Pillow: Pillow: Denial of Service via specially crafted coordinate input
A flaw was found in Pillow, a Python imaging library. A malicious actor could exploit this vulnerability by providing specially crafted nested lists as coordinates to image processing APIs within Pillow. This could lead to a heap buffer overflow, potentially causing a denial of service in applications using the library.
Statement: This Moderate impact vulnerability in the Pillow Python imaging library could lead to a denial of service. Applications processing untrusted image data that utilize specific Pillow APIs, such as `ImagePath.Path`, `ImageDraw.ImageDraw.polygon`, or `ImageDraw.ImageDraw.line`, with specially crafted nested list coordinates are susceptible to a heap buffer overflow.
Package: exploit-intellige
No detection rules found.
No public exploits indexed.
2026-05-09
Published