<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:52:21.860602+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:4149</id>
    <title>ALSA-2021:4149 — Moderate: python-pillow security update</title>
    <updated>2026-10-03T19:52:22.166599+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python3-pillow</p>
<p>The python-pillow packages contain a Python image processing library that provides extensive file format support, an efficient internal representation, and powerful image-processing capabilities.</p>
<p>Security Fix(es):</p>
<p>* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25287)</p>
<p>* python-pillow: Out-of-bounds read in J2K image reader (CVE-2021-25288)</p>
<p>* python-pillow: Negative-offset memcpy in TIFF image reader (CVE-2021-25290)</p>
<p>* python-pillow: Regular expression DoS in PDF format parser (CVE-2021-25292)</p>
<p>* python-pillow: Out-of-bounds read in SGI RLE image reader (CVE-2021-25293)</p>
<p>* python-pillow: Excessive memory allocation in BLP image reader (CVE-2021-27921)</p>
<p>* python-pillow: Excessive memory allocation in ICNS image reader (CVE-2021-27922)</p>
<p>* python-pillow: Excessive memory allocation in ICO image reader (CVE-2021-27923)</p>
<p>* python-pillow: Excessive memory allocation in PSD image reader (CVE-2021-28675)</p>
<p>* python-pillow: Infinite loop in FLI image reader (CVE-2021-28676)</p>
<p>* python-pillow: Excessive CPU use in EPS image reader (CVE-2021-28677)</p>
<p>* python-pillow: Excessive looping in BLP image reader (CVE-2021-28678)</p>
<p>* python-pillow: Buffer overflow in image convert function (CVE-2021-34552)</p>
<p>* python-pillow: Buffer over-read in PCX image reader (CVE-2020-35653)</p>
<p>* python-pillow: Buffer over-read in SGI RLE image reader (CVE-2020-35655)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related informati…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:4149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-pillow-2021-27922</id>
    <title>BIT-pillow-2021-27922</title>
    <updated>2026-10-03T19:52:22.166685+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: pillow</p>
<p>Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-pillow-2021-27922"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-pillow-cve-2021-27922</id>
    <title>BREW-pillow-CVE-2021-27922</title>
    <updated>2026-10-03T19:52:22.166710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: pillow</p>
<p>Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-pillow-cve-2021-27922"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-14763</id>
    <title>cnvd-2021-14763</title>
    <updated>2026-10-03T19:52:22.166729+00:00</updated>
    <content>cnvd-2021-14763</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-14763"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-249892</id>
    <title>EUVD-2026-249892</title>
    <updated>2026-10-03T19:52:22.166743+00:00</updated>
    <content>EUVD-2026-249892</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-249892"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-27922</id>
    <title>fkie_cve-2021-27922</title>
    <updated>2026-10-03T19:52:22.166755+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-27922"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3wvg-mj6g-m9cv</id>
    <title>GHSA-3wvg-mj6g-m9cv — Pillow Uncontrolled Resource Consumption</title>
    <updated>2026-10-03T19:52:22.166775+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pillow</p>
<p>Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3wvg-mj6g-m9cv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-27922</id>
    <title>gsd-2021-27922</title>
    <updated>2026-10-03T19:52:22.166793+00:00</updated>
    <content>gsd-2021-27922</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-27922"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1127</id>
    <title>OESA-2021-1127 — python-pillow security update</title>
    <updated>2026-10-03T19:52:22.166804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS: python-pillow</p>
<p>Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.

Security Fix(es):

In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.(CVE-2020-35655)

Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.(CVE-2021-27921)

Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.(CVE-2021-27922)

Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.(CVE-2021-27923)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1134-1</id>
    <title>openSUSE-SU-2021:1134-1 — Security update for python-CairoSVG, python-Pillow</title>
    <updated>2026-10-03T19:52:22.166830+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-CairoSVG, python-Pillow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:1134-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2021-41</id>
    <title>PYSEC-2021-41</title>
    <updated>2026-10-03T19:52:22.166855+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pillow</p>
<p>Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2021-41"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:3917</id>
    <title>RHSA-2021:3917 — Red Hat Security Advisory: Red Hat Quay v3.6.0 security, bug fix and enhancement update</title>
    <updated>2026-10-03T19:52:22.166872+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-debug: Regular expression Denial of Service nodejs-mime: Regular expression Denial of Service nodejs-is-my-json-valid: ReDoS when validating JSON fields with email format nodejs-braces: Regular Expression Denial of Service (ReDoS) in lib/parsers.js lodash: Prototype pollution in utilities function hoek: Prototype pollution in utilities function nodejs-url-parse: incorrect hostname in url parsing nodejs-extend: Prototype pollution can allow attackers to modify object properties nodejs-stringstream: out-of-bounds read leading to uninitialized memory exposure nodejs-handlebars: lookup helper fails to properly validate templates allowing for arbitrary JavaScript execution nodejs-handlebars: an endless loop while processing specially-crafted templates leads to DoS lodash: uncontrolled resource consumption in Data handler causing denial of service nodejs-yargs-parser: prototype pollution vulnerability nodejs-lodash: prototype pollution in zipObjectDeep function nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function nodejs-highlight-js: prototype pollution via a crafted HTML code block urijs: Hostname spoofing via backslashes in URL python-pillow: Buffer over-read in PCX image reader python-pillow: decoding crafted YCbCr files could result in heap-based buffer overflow browserslist: parsing of invalid queries could result in Regular Expression Denial of Service (ReDoS) nodejs-postcss: Regular expression denial of service during source map parsing no…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:3917"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:1938-1</id>
    <title>SUSE-SU-2021:1938-1 — Security update for python-Pillow</title>
    <updated>2026-10-03T19:52:22.166945+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Pillow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:1938-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-27922</id>
    <title>UBUNTU-CVE-2021-27922</title>
    <updated>2026-10-03T19:52:22.166967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: pillow, Ubuntu:18.04:LTS: pillow, Ubuntu:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2</p>
<p>Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-27922"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1835</id>
    <title>WID-SEC-W-2022-1835 — Red Hat Enterprise Linux (python-pillow): Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:52:22.166989+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in python-pillow ausnutzen, um einen Denial of Service Angriff durchzuführen und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1835"/>
  </entry>
</feed>
