CVE-2026-42309

EUVD-2026-28901
Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This issue has been patched in version 12.2.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.2%
Affected Products (NVD)
VendorProductVersion
pythonpillow
11.2.1 ≤
𝑥
< 12.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pillow
bookworm
9.4.0-1.1+deb12u1
fixed
bookworm (security)
9.4.0-1.1+deb12u1
fixed
bullseye
8.1.2+dfsg-0.3+deb11u2
fixed
bullseye (security)
8.1.2+dfsg-0.3+deb11u3
fixed
forky
12.3.0-1
fixed
sid
12.3.0-1
fixed
trixie
11.1.0-5+deb13u4
fixed
trixie (security)
11.1.0-5+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pillow
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
Fixed 11.3.0-1ubuntu1.3
released
resolute
Fixed 12.1.1-2ubuntu1.2
released
trusty
not-affected
xenial
not-affected
pillow-python2
focal
not-affected
jammy
dne
noble
dne
questing
dne
resolute
dne