cbcvebase.
CVE-2026-59205
published 2026-07-14

CVE-2026-59205: Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.39%
31.7th percentile
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.

Affected

77 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platform-25lightspeed-chatbot-rhel8
ansible-automation-platform-26hub-rhel9
ansible-automation-platform-26lightspeed-chatbot-rhel9
ansible-automation-platform-27hub-rhel9
ansible-automation-platform-27lightspeed-chatbot-rhel9
ansible-automation-platformautomation-dashboard-rhel9
exploit-intelligence-tech-previewvulnerability-analysis-rhel9
lightspeed-corelightspeed-stack-rhel9
lightspeed-corerag-tool-cpu-rhel9
lightspeed-corerag-tool-cuda-12.9-rhel9
openshift-lightspeedlightspeed-service-api-rhel9
python-pillowpillow< 12.3.012.3.0
pythonpillow< 12.3.012.3.0
pythonpillow>= 0 < 12.3.012.3.0
quayquay-rhel8
quayquay-rhel9
rhaiimodel-opt-cuda-rhel9
rhaiivllm-cpu-rhel9
rhaiivllm-cuda-rhel9
rhaiivllm-gaudi-rhel9
rhaiivllm-neuron-rhel9
rhaiivllm-rocm-rhel9
rhaiivllm-spyre-rhel9
rhaiivllm-tpu-rhel9
rhaiismodel-opt-cuda-rhel9

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.