CVE-2016-4009: Python Pillow
Critical severity, CVSS 9.8. EPSS: 7.9% chance of exploitation in the next 30 days.
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.
Affected products
- Python Pillow: up to and including 3.1.0
Published 2016-04-13. Last modified 2026-06-17.