Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

Python Pillow library can run malicious code

published 21 days ago
Summary

The Pillow image‑processing library used in many Python applications has a flaw that could let an attacker execute unwanted code when processing crafted image files. This could affect any system that uses Pillow to handle images, potentially leading to data loss or unauthorized access. Apply the latest Pillow update from your package manager as soon as possible to close the risk.

What to do
  • Update redhat python-pillow to version 0:5.1.1-20.el8_6.1.
  • Update redhat python-pillow-debuginfo to version 0:5.1.1-20.el8_6.1.
  • Update redhat python-pillow-debugsource to version 0:5.1.1-20.el8_6.1.
  • Update redhat python3-pillow to version 0:5.1.1-20.el8_6.1.
  • Update redhat python3-pillow-debuginfo to version 0:5.1.1-20.el8_6.1.
  • Update redhat python3-pillow-tk-debuginfo to version 0:5.1.1-20.el8_6.1.
Affected software
Ecosystem VendorProductAffected versions
Red Hat:rhel_aus:8.6::appstream redhat python-pillow < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Red Hat:rhel_aus:8.6::appstream redhat python-pillow-debuginfo < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Red Hat:rhel_aus:8.6::appstream redhat python-pillow-debugsource < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Red Hat:rhel_aus:8.6::appstream redhat python3-pillow < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Red Hat:rhel_aus:8.6::appstream redhat python3-pillow-debuginfo < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Red Hat:rhel_aus:8.6::appstream redhat python3-pillow-tk-debuginfo < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Red Hat:rhel_eus_long_life:8.6::appstream redhat python-pillow < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Red Hat:rhel_eus_long_life:8.6::appstream redhat python-pillow-debuginfo < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Red Hat:rhel_eus_long_life:8.6::appstream redhat python-pillow-debugsource < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Red Hat:rhel_eus_long_life:8.6::appstream redhat python3-pillow < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Red Hat:rhel_eus_long_life:8.6::appstream redhat python3-pillow-debuginfo < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Red Hat:rhel_eus_long_life:8.6::appstream redhat python3-pillow-tk-debuginfo < 0:5.1.1-20.el8_6.1
Fix: upgrade to 0:5.1.1-20.el8_6.1
Original advisory text
Red Hat Security Advisory: python-pillow security update
Severity
9.1 Critical
CVSS 3.1: 9.1 (OSV)
Timeline
Published14 Aug 2026
Updated22 Aug 2026
First seen22 Aug 2026
Sources
Monitor software like this
Free during beta