{"id":"GHSA-5xmw-vc9v-4wf2","summary":"Pillow has a heap buffer overflow with nested list coordinates","details":"Passing nested lists as coordinates to APIs that accept coordinates such as `ImagePath.Path`, `ImageDraw.ImageDraw.polygon` and `ImageDraw.ImageDraw.line` could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This was introduced in Pillow 11.2.1.","aliases":["BIT-pillow-2026-42309","CVE-2026-42309","PYSEC-2026-2251"],"modified":"2026-07-17T21:05:33.464599087Z","published":"2026-05-04T20:18:27Z","database_specific":{"cwe_ids":["CWE-122"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-04T20:18:27Z","nvd_published_at":"2026-05-09T06:16:10Z"},"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5xmw-vc9v-4wf2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42309"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/releases/tag/12.2.0"}],"affected":[{"package":{"name":"pillow","ecosystem":"PyPI","purl":"pkg:pypi/pillow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.2.1"},{"fixed":"12.2.0"}]}],"versions":["11.2.1","11.3.0","12.0.0","12.1.0","12.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5xmw-vc9v-4wf2/GHSA-5xmw-vc9v-4wf2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}