CVE security advisories and vulnerability history for pillow by python-pillow.
73
Total CVEs
Published
0
In CISA KEV
Exploited in the wild
6
Public exploits
With known exploit
5.3
Avg CVSS
2016–2026
Last updated
Overview
python-pillow pillow has 73 published CVE records since 2016, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 6 have a known public exploit. The average CVSS base score across scored CVEs is 5.3.
This page aggregates every publicly disclosed vulnerability (CVE) affecting python-pillow pillow, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of python-pillow pillow's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical1
High6
Medium8
Low9
49 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of python-pillow pillow's CVEs are currently listed in CISA's KEV catalog.
Public exploits
6
6 of python-pillow pillow's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every python-pillow pillow version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about python-pillow pillow vulnerabilities.
How many CVEs does python-pillow pillow have?
python-pillow pillow has 73 published CVE records since 2016.
How many python-pillow pillow CVEs are in CISA KEV?
None of python-pillow pillow's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Are there public exploits for python-pillow pillow vulnerabilities?
Yes — 6 of python-pillow pillow's CVEs have a known public exploit.
Which versions of python-pillow pillow are affected?
102 distinct python-pillow pillow versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in python-pillow pillow CVEs?
python-pillow pillow's CVEs most often map to these CWE weakness types: CWE-125 (Out-of-bounds Read), CWE-190 (Integer Overflow or Wraparound), CWE-122 (Heap-based Buffer Overflow), CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer).
How many critical python-pillow pillow vulnerabilities are there?
python-pillow pillow has 1 critical and 6 high-severity CVEs.
What is the average severity of python-pillow pillow CVEs?
The average CVSS base score across python-pillow pillow's scored CVEs is 5.3.