{"id":"CVE-2026-59204","summary":"Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service","details":"Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.","aliases":["BIT-pillow-2026-59204","GHSA-vjc4-5qp5-m44j","PYSEC-2026-3496"],"modified":"2026-07-23T15:14:50.541013675Z","published":"2026-07-14T15:38:29.545Z","related":["SUSE-SU-2026:3084-1","openSUSE-SU-2026:11283-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-789"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59204.json"},"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.3.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59204.json"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59204"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/pull/9704"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/python-pillow/pillow","events":[{"introduced":"e0e353c0ef7516979a9aedce3792596649ce4433"},{"fixed":"bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d"},{"fixed":"13ada41172142f2fd9f0906f615a00ea623a11ca"}],"database_specific":{"cpe":"cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.2.0"},{"fixed":"12.3.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["12.2.0","12.1.0","12.0.0","11.3.0","11.2.1","11.1.0","11.0.0","10.4.0","10.3.0","10.2.0","10.1.0","10.0.0","9.5.0","9.4.0","9.3.0","9.2.0","9.1.0","9.0.0","8.4.0","8.3.0","8.2.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-59204.json","vanir_signatures_modified":"2026-07-23T08:16:30Z","vanir_signatures":[{"target":{"file":"src/libImaging/Jpeg2KDecode.c"},"deprecated":false,"digest":{"line_hashes":["291688561660707804276815887228166717799","264534465699635397772598286647326644689","292509477046047446378274593332551812301","189228586624185902837887542284463616471","105633872374323187754703844676181373460","23905744739649837941053605454746852793","246883239106134902990532735369164409266"],"threshold":0.9},"id":"CVE-2026-59204-6289961c","signature_type":"Line","signature_version":"v1","source":"https://github.com/python-pillow/pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca"},{"target":{"file":"src/libImaging/Jpeg2KDecode.c","function":"j2k_decode_entry"},"deprecated":false,"digest":{"length":4860,"function_hash":"172830296100755463424665802641356405889"},"id":"CVE-2026-59204-7f7a3275","signature_type":"Function","signature_version":"v1","source":"https://github.com/python-pillow/pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}