CVE-2026-59200 - High Severity Vulnerability
Vulnerable Library - Pillow-9.1.0-cp310-cp310-macosx_10_9_x86_64.whl
Python Imaging Library (Fork)
Library home page: https://files.pythonhosted.org/packages/0c/6a/f0021d1959d2778289476d60470aba964fb08dda587ec53929272e5ed3dc/Pillow-9.1.0-cp310-cp310-macosx_10_9_x86_64.whl
Dependency Hierarchy:
- darts-0.13.1-py3-none-any.whl (Root Library)
- prophet-1.0.1.tar.gz
- matplotlib-3.5.1-cp39-cp39-manylinux_2_5_x86_64.manylinux1_x86_64.whl
- ❌ Pillow-9.1.0-cp310-cp310-macosx_10_9_x86_64.whl (Vulnerable Library)
Found in base branch: main
Vulnerability Details
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.
Publish Date: 2026-07-14
URL: CVE-2026-59200
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-jjj6-mw9f-p565
Release Date: 2026-07-14
Fix Resolution (pillow): 12.3.0
Direct dependency fix Resolution (darts): 0.14.0
Step up your Open Source Security Game with Mend here
CVE-2026-59200 - High Severity Vulnerability
Python Imaging Library (Fork)
Library home page: https://files.pythonhosted.org/packages/0c/6a/f0021d1959d2778289476d60470aba964fb08dda587ec53929272e5ed3dc/Pillow-9.1.0-cp310-cp310-macosx_10_9_x86_64.whl
Dependency Hierarchy:
Found in base branch: main
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.
Publish Date: 2026-07-14
URL: CVE-2026-59200
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: GHSA-jjj6-mw9f-p565
Release Date: 2026-07-14
Fix Resolution (pillow): 12.3.0
Direct dependency fix Resolution (darts): 0.14.0
Step up your Open Source Security Game with Mend here