CVE-2026-59205
Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch
7.5
HIGH
CVSS 3.1
EPSS 0.39%
Description
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.
How to fix CVE-2026-59205
To remediate CVE-2026-59205, upgrade the affected package to a fixed version below.
- —upgrade to 12.3.0 or later
- —no fix listed
- —upgrade to 12.3.0 or later
- —upgrade to 12.3.0 or later
Is CVE-2026-59205 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 12.3.0
- from 0
- from 0, < 12.3.0
- from 0, < 12.3.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |