HIGH 8.2
PYSEC-2026-3454
Quick fix
PYSEC-2026-3454 — pillow: upgrade to the fixed version with the command below.
pip install --upgrade 'pillow>=12.3.0' Details
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0 [ADVISORY]
- https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1 [FIX]
- https://github.com/python-pillow/Pillow/pull/9695 [FIX]
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr [EVIDENCE]