CVE-2026-59205: Python Pillow
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.
Affected products
- Python Pillow: before 12.3.0 (fixed in 12.3.0)
Published 2026-07-14. Last modified 2026-07-14.