Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
Python Pillow library can run malicious code
published 21 days ago
Summary
The Pillow image‑processing library used in many Python applications has a flaw that could let an attacker execute unwanted code when processing crafted image files. This could affect any system that uses Pillow to handle images, potentially leading to data loss or unauthorized access. Apply the latest Pillow update from your package manager as soon as possible to close the risk.
What to do
- Update redhat python-pillow to version 0:5.1.1-20.el8_6.1.
- Update redhat python-pillow-debuginfo to version 0:5.1.1-20.el8_6.1.
- Update redhat python-pillow-debugsource to version 0:5.1.1-20.el8_6.1.
- Update redhat python3-pillow to version 0:5.1.1-20.el8_6.1.
- Update redhat python3-pillow-debuginfo to version 0:5.1.1-20.el8_6.1.
- Update redhat python3-pillow-tk-debuginfo to version 0:5.1.1-20.el8_6.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Red Hat:rhel_aus:8.6::appstream | redhat | python-pillow |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
| Red Hat:rhel_aus:8.6::appstream | redhat | python-pillow-debuginfo |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
| Red Hat:rhel_aus:8.6::appstream | redhat | python-pillow-debugsource |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
| Red Hat:rhel_aus:8.6::appstream | redhat | python3-pillow |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
| Red Hat:rhel_aus:8.6::appstream | redhat | python3-pillow-debuginfo |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
| Red Hat:rhel_aus:8.6::appstream | redhat | python3-pillow-tk-debuginfo |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
| Red Hat:rhel_eus_long_life:8.6::appstream | redhat | python-pillow |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
| Red Hat:rhel_eus_long_life:8.6::appstream | redhat | python-pillow-debuginfo |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
| Red Hat:rhel_eus_long_life:8.6::appstream | redhat | python-pillow-debugsource |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
| Red Hat:rhel_eus_long_life:8.6::appstream | redhat | python3-pillow |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
| Red Hat:rhel_eus_long_life:8.6::appstream | redhat | python3-pillow-debuginfo |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
| Red Hat:rhel_eus_long_life:8.6::appstream | redhat | python3-pillow-tk-debuginfo |
< 0:5.1.1-20.el8_6.1 Fix: upgrade to 0:5.1.1-20.el8_6.1
|
Original advisory text
Red Hat Security Advisory: python-pillow security update
References
- https://access.redhat.com/errata/RHSA-2026:54528 Vendor Advisory
- https://access.redhat.com/security/updates/classification/#important Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2500043 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2500057 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54528.... Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-54058 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-54058 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-54058 Vendor Advisory
- https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90... Third Party Advisory
- https://github.com/python-pillow/Pillow/pull/9719 Third Party Advisory
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0 Third Party Advisory
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-59197 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-59197 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-59197 Vendor Advisory
- https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b078... Third Party Advisory
- https://github.com/python-pillow/Pillow/pull/9695 Third Party Advisory
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr Third Party Advisory
Severity
9.1
Critical
CVSS 3.1: 9.1 (OSV)
Timeline
Published14 Aug 2026
Updated22 Aug 2026
First seen22 Aug 2026
Sources
RHSA-2026:54528 · OSV
Monitor software like this
Free during beta