Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.
References
| Link | Resource |
|---|---|
| https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721 | Patch |
| https://github.com/python-pillow/Pillow/pull/9715 | Issue Tracking Patch |
| https://github.com/python-pillow/Pillow/releases/tag/12.3.0 | Release Notes |
| https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6 | Exploit Vendor Advisory |
| https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6 | Exploit Vendor Advisory |
Configurations
History
14 Jul 2026, 20:09
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:* | |
| First Time |
Python
Python pillow |
|
| References | () https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721 - Patch | |
| References | () https://github.com/python-pillow/Pillow/pull/9715 - Issue Tracking, Patch | |
| References | () https://github.com/python-pillow/Pillow/releases/tag/12.3.0 - Release Notes | |
| References | () https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6 - Exploit, Vendor Advisory |
14 Jul 2026, 18:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6 - |
14 Jul 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 16:17
Updated : 2026-07-14 20:09
NVD link : CVE-2026-59205
Mitre link : CVE-2026-59205
CVE.ORG link : CVE-2026-59205
JSON object : View
Products Affected
python
- pillow
CWE
CWE-787
Out-of-bounds Write
