CVE-2026-59204·Python vulnerability
Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.
- Severity
- high
- Software
- Python
- Fixed in
- 12.3.0
- Published
- 2026-07-14
Affected versions
From: 8.2.0
Until: 12.3.0
Fixed in: 12.3.0
How to fix this CVE
Update Pillow to version 12.3.0 or later to remediate a memory exhaustion vulnerability in JPEG2000 image processing. The vulnerability allows specially crafted tiled JPEG2000 files to consume excessive memory during decoding, potentially causing application crashes. Ensure all systems running Python with Pillow between versions 8.2.0 and 12.2.0 are patched immediately.
sudo dnf update python3-pillowDefensia detects this vulnerability
How to check if you are affected
- Check installed Pillow version: python3 -c "import PIL; print(PIL.__version__)"
- Identify if JPEG2000 files are processed by your application by reviewing code for references to 'jp2', 'jpx', or 'j2k' file handling
- Search application logs for out-of-memory errors (OOMKilled, MemoryError) correlated with JPEG2000 image processing timestamps
- Verify the patch by running python3 -c "import PIL; print(PIL.__version__)" and confirming version is 12.3.0 or higher
FAQ
What is CVE-2026-59204?
CVE-2026-59204 is a memory exhaustion vulnerability in Pillow's JPEG2000 decoder that incorrectly accumulates memory width calculations across image tiles instead of resetting per tile, allowing attackers to craft malicious JPEG2000 files that trigger excessive memory consumption and denial-of-service conditions.
Is CVE-2026-59204 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploits are available. However, the vulnerability is straightforward to exploit and should be patched proactively.
What versions of Python are affected by CVE-2026-59204?
The vulnerability affects Pillow versions 8.2.0 through 12.2.0. It is resolved in Pillow 12.3.0 and later. Any Python installation using an affected version of Pillow is vulnerable.
How do I check if my server is vulnerable to CVE-2026-59204?
Run 'python3 -c "import PIL; print(PIL.__version__)"' and compare the version against the affected range (8.2.0-12.2.0). If the installed version falls within this range, your server is vulnerable.
Does Defensia detect CVE-2026-59204?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Pillow is installed on a monitored server and the version is between 8.2.0 and 12.2.0, CVE-2026-59204 will appear in your dashboard with remediation steps.
Related Python CVEs
References
- https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca
- https://github.com/python-pillow/Pillow/pull/9704
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-59204. Free for 1 server.
Get started free