CVE-2026-59205
גבוהה 7.5
תיאור (מקור, אנגלית)
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-14/8/2026
- CWE
- CWE-787
מוצרים מושפעים
python: pillow
קישורים
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6 ExploitVendor Advisory
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6 ExploitVendor Advisory
- https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e8… Patch
- https://github.com/python-pillow/Pillow/pull/9715 Issue TrackingPatch
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0 Release Notes