{"id":"CVE-2026-28231","aliases":["GHSA-5gjj-6r7v-ph3x","PYSEC-2026-2248","PYSEC-2026-2258"],"url":"https://o3.security/vulnerability/CVE-2026-28231","summary":"pillow_heif Has Integer Overflow in Encode Path Buffer Validation that Leads to Heap Out-of-Bounds Read","details":"pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds read. This can lead to information disclosure (server heap memory leaking into encoded images) or denial of service (process crash). No special configuration is required — this triggers under default settings. Version 1.3.0 fixes the issue.","published":"2026-02-27T20:13:45.195Z","modified":"2026-08-12T15:32:10.161907Z","cvss":null,"epss":{"score":0.00632,"percentile":0.4805,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pi-heif","fixedVersion":"1.3.0"},{"ecosystem":"PyPI","name":"pillow-heif","fixedVersion":"1.3.0"}],"fix":{"url":"https://github.com/bigcat88/pillow_heif/commit/8305a15d3780c533b762578cbe987d27a2c59c7a","label":"bigcat88/pillow_heif@8305a15"},"references":[{"type":"WEB","url":"https://github.com/bigcat88/pillow_heif/releases/tag/v1.3.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28231.json"},{"type":"ADVISORY","url":"https://github.com/bigcat88/pillow_heif/security/advisories/GHSA-5gjj-6r7v-ph3x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28231"},{"type":"FIX","url":"https://github.com/bigcat88/pillow_heif/commit/8305a15d3780c533b762578cbe987d27a2c59c7a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:32:10.161907Z"}}