{"api_version":"v1","generated_at":"2026-10-06T16:10:00+00:00","product":{"cve_count":20,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-python-pillow-pillow-ce9e5216b74d","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/pillow","name":"Pillow","next_cursor":null,"observations":[{"affected":"< 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-54058","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54058","fixed":"12.3.0.","last_modified":"2026-07-14T17:54:25.654Z","patch_url":"https://github.com/python-pillow/Pillow/pull/9719","primary_source":"","published":"2026-07-14T16:27:38.050Z"},{"affected":"< 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-59197","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59197","fixed":"12.3.0.","last_modified":"2026-07-21T18:50:40.019Z","patch_url":"https://github.com/python-pillow/Pillow/pull/9695","primary_source":"","published":"2026-07-14T16:25:23.520Z"},{"affected":">= 5.1.0, < 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-59200","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59200","fixed":"12.3.0.","last_modified":"2026-07-14T19:52:06.407Z","patch_url":"https://github.com/python-pillow/Pillow/pull/9718","primary_source":"","published":"2026-07-14T16:09:05.091Z"},{"affected":">= 5.2.0, < 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-59198","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59198","fixed":"12.3.0.","last_modified":"2026-07-14T19:55:56.380Z","patch_url":"https://github.com/python-pillow/Pillow/pull/9709","primary_source":"","published":"2026-07-14T16:07:56.562Z"},{"affected":"< 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-59205","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59205","fixed":"12.3.0.","last_modified":"2026-07-14T17:31:36.064Z","patch_url":"https://github.com/python-pillow/Pillow/pull/9715","primary_source":"","published":"2026-07-14T15:48:39.962Z"},{"affected":">= 12.0.0, < 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-59203","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59203","fixed":"12.3.0.","last_modified":"2026-07-15T13:52:17.491Z","patch_url":"https://github.com/python-pillow/Pillow/pull/9708","primary_source":"","published":"2026-07-14T15:43:58.333Z"},{"affected":"< 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-59199","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59199","fixed":"12.3.0.","last_modified":"2026-07-15T14:53:39.590Z","patch_url":"https://github.com/python-pillow/Pillow/pull/9703","primary_source":"","published":"2026-07-14T15:42:15.071Z"},{"affected":">= 8.2.0, < 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-59204","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59204","fixed":"12.3.0.","last_modified":"2026-07-21T18:41:18.660Z","patch_url":"https://github.com/python-pillow/Pillow/pull/9704","primary_source":"","published":"2026-07-14T15:38:29.545Z"},{"affected":"< 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-55379","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55379","fixed":"12.3.0.","last_modified":"2026-07-06T19:17:03.941Z","patch_url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d","primary_source":"","published":"2026-07-06T18:52:11.633Z"},{"affected":"< 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-55380","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55380","fixed":"12.3.0.","last_modified":"2026-07-06T19:23:30.046Z","patch_url":"https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675","primary_source":"","published":"2026-07-06T18:50:14.789Z"},{"affected":"< 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-54060","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54060","fixed":"12.3.0.","last_modified":"2026-07-07T14:08:14.588Z","patch_url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d","primary_source":"","published":"2026-07-06T18:49:23.788Z"},{"affected":"< 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-54059","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54059","fixed":"12.3.0.","last_modified":"2026-07-07T16:57:53.021Z","patch_url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d","primary_source":"","published":"2026-07-06T18:46:09.433Z"},{"affected":"< 12.3.0","affected_versions_present":true,"cve_id":"CVE-2026-55798","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55798","fixed":"12.3.0.","last_modified":"2026-07-07T15:19:40.072Z","patch_url":"https://github.com/python-pillow/Pillow/commit/8404ea5fe5df40fc34aa1e51403dd6fce0778b8a","primary_source":"","published":"2026-07-06T18:44:38.441Z"},{"affected":">= 10.3.0, < 12.2.0","affected_versions_present":true,"cve_id":"CVE-2026-42311","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42311","fixed":"For more information visit https://access.redhat.com/errata/RHSA-2026:61628","last_modified":"2026-05-12T02:24:33.053Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-42311","primary_source":"","published":"2026-05-09T04:11:58.092Z"},{"affected":">= 4.2.0, < 12.2.0","affected_versions_present":true,"cve_id":"CVE-2026-42310","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42310","fixed":"For more information visit https://access.redhat.com/errata/RHSA-2026:16008","last_modified":"2026-05-12T18:31:10.271Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-42310","primary_source":"","published":"2026-05-09T04:10:48.395Z"},{"affected":"< 12.2.0","affected_versions_present":true,"cve_id":"CVE-2026-42308","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42308","fixed":"For more information visit https://access.redhat.com/errata/RHSA-2026:16008","last_modified":"2026-05-11T15:03:00.916Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-42308","primary_source":"","published":"2026-05-09T04:09:01.631Z"},{"affected":">= 11.2.1, < 12.2.0","affected_versions_present":true,"cve_id":"CVE-2026-42309","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42309","fixed":"For more information visit https://access.redhat.com/errata/RHSA-2026:16008","last_modified":"2026-05-11T14:48:18.204Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-42309","primary_source":"","published":"2026-05-09T04:08:10.517Z"},{"affected":"Pillow: >= 10.3.0, < 12.2.0","affected_versions_present":true,"cve_id":"CVE-2026-40192","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40192","fixed":"RHSA-2026:24761: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9","last_modified":"2026-09-10T12:04:47.474Z","patch_url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j","primary_source":"","published":"2026-04-15T22:53:56.147Z"},{"affected":"Pillow: >= 10.3.0, < 12.1.1","affected_versions_present":true,"cve_id":"CVE-2026-25990","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25990","fixed":"RHSA-2026:6278: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9","last_modified":"2026-09-16T12:04:20.759Z","patch_url":"https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa","primary_source":"","published":"2026-02-11T20:53:52.524Z"},{"affected":">= 11.2.0, < 11.3.0","affected_versions_present":true,"cve_id":"CVE-2025-48379","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-48379","fixed":"For more information visit https://access.redhat.com/errata/RHSA-2025:15839","last_modified":"2025-07-01T19:42:22.348Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-48379","primary_source":"","published":"2025-07-01T18:33:30.687Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"python-pillow"}}
