CVE-2026-42309

EUVD-2026-28901
Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This issue has been patched in version 12.2.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Debian logo
Debian Releases
Debian Product
Codename
pillow
bookworm
9.4.0-1.1+deb12u1
fixed
bookworm (security)
9.4.0-1.1+deb12u1
fixed
bullseye
8.1.2+dfsg-0.3+deb11u2
fixed
bullseye (security)
8.1.2+dfsg-0.3+deb11u3
fixed
forky
12.2.0-1
fixed
sid
12.2.0-1
fixed
trixie
11.1.0-5+deb13u1
fixed
trixie (security)
11.1.0-5+deb13u2
fixed