Vulnerability index

Browse CVEs

208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pillow HIGH 8.2
CVE-2026-59197

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very …

Fix: 12.3.0+
Fix from $1,950 2026-07-14
Pillow HIGH 7.5
CVE-2026-59200

Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize se…

Fix: 12.3.0+
Fix from $1,950 2026-07-14
Pillow CRITICAL 9.1
CVE-2026-54058

Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec p…

Fix: 12.3.0+
Fix from $2,300 2026-07-14
Pillow HIGH 7.5
CVE-2026-59203

Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%B…

Fix: 12.3.0+
Fix from $1,950 2026-07-14
Pillow HIGH 7.5
CVE-2026-59204

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a…

Fix: 12.3.0+
Fix from $1,950 2026-07-14
Pillow HIGH 7.5
CVE-2026-59205

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corr…

Fix: 12.3.0+
Fix from $1,950 2026-07-14
Pillow HIGH 7.5
CVE-2026-59198

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image wit…

Fix: 12.3.0+
Fix from $1,950 2026-07-14
Pillow HIGH 7.5
CVE-2026-59199

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coo…

Fix: 12.3.0+
Fix from $1,950 2026-07-14
Python HIGH 7.5
CVE-2026-15308

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processi…

Fix: 3.15.0+
Fix from $1,950 2026-07-09
Setuptools MEDIUM 6.1
CVE-2026-59890

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANI…

Fix: 83.0.0+
Fix from $1,600 2026-07-08
Pillow HIGH 7.5
CVE-2026-54059

Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed…

Fix: 12.3.0+
Fix from $1,950 2026-07-06
Pillow HIGH 7.5
CVE-2026-54060

Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.…

Fix: 12.3.0+
Fix from $1,950 2026-07-06
Pillow HIGH 7.5
CVE-2026-55379

Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passe…

Fix: 12.3.0+
Fix from $1,950 2026-07-06
Pillow HIGH 7.5
CVE-2026-55380

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored t…

Fix: 12.3.0+
Fix from $1,950 2026-07-06
Python MEDIUM 5.3
CVE-2026-4360

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content fr…

Fix: 3.1.5+
Fix from $1,600 2026-06-30
Python MEDIUM 5.5
CVE-2026-0864

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resultin…

Fix unknown
Fix from $1,600 2026-06-23
Urllib3 HIGH 7.5
CVE-2026-44432

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portio…

Fix: 2.7.0+
Fix from $1,950 2026-05-13
Urllib3 MEDIUM 5.3
CVE-2026-44431

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.conn…

Fix: 2.7.0+
Fix from $1,600 2026-05-13
Python HIGH 7.5
CVE-2026-7210

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to t…

Fix: 3.13.14 / 3.14.6+
Fix from $1,950 2026-05-11
Pillow HIGH 7.8
CVE-2026-42311

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, po…

Fix: 12.2.0+
Fix from $1,950 2026-05-09
Pillow MEDIUM 5.5
CVE-2026-42309

Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates…

Fix: 12.2.0+
Fix from $1,600 2026-05-09
Pillow MEDIUM 5.5
CVE-2026-42310

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to ha…

Fix: 12.2.0+
Fix from $1,600 2026-05-09
Pillow MEDIUM 5.5
CVE-2026-42308

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track …

Fix: 12.2.0+
Fix from $1,600 2026-05-09
Python HIGH 7.5
CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted o…

Fix: after 3.14.4
Fix from $1,950 2026-04-27
Python MEDIUM 6.1
CVE-2026-6019

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML …

Fix: 3.13.14+
Fix from $1,600 2026-04-22
Pillow HIGH 7.5
CVE-2026-40192

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, …

Fix: 12.2.0+
Fix from $1,950 2026-04-15
Pymanager HIGH 7.8
CVE-2026-5271

pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current working directory. As a resu…

No fix yet
Fix from $1,950 2026-04-01
Requests MEDIUM 5.5
CVE-2026-25645

Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when ex…

Fix: 2.33.0+
Fix from $1,600 2026-03-25
Python HIGH 7.5
CVE-2026-4224

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stac…

Fix: 3.10.0 / 3.13.13+
Fix from $1,950 2026-03-16
Python HIGH 7.5
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling…

Fix: 3.13.13 / 3.14.4+
Fix from $1,950 2026-03-16