{"id":"CVE-2026-59204","aliases":["BIT-pillow-2026-59204","GHSA-vjc4-5qp5-m44j","PYSEC-2026-3496"],"url":"https://o3.security/vulnerability/CVE-2026-59204","summary":"Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service","details":"Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.","published":"2026-07-14T15:38:29.545Z","modified":"2026-08-27T18:26:19.251512580Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pillow","fixedVersion":"12.3.0"}],"fix":{"url":"https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca","label":"python-pillow/Pillow@13ada41"},"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59204.json"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59204"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9704"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T18:26:19.251512580Z"}}