CVE-2026-59205

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
14/07/2026
Last modified:
14/07/2026

Description

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:* 12.3.0 (excluding)