CVE-2016-4009: Python Pillow

Critical severity, CVSS 9.8. EPSS: 7.9% chance of exploitation in the next 30 days.

Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which triggers a heap-based buffer overflow.

Affected products

  • Python Pillow: up to and including 3.1.0

Published 2016-04-13. Last modified 2026-06-17.