CVE-2019-16865: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
Affected products
- Fedoraproject Fedora: version 30 only; version 31 only
- Python Pillow: before 6.2.0 (fixed in 6.2.0)
Published 2019-10-04. Last modified 2026-06-17.