Safety vulnerability ID: 41271
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Pillow from 5.2.0 and before 8.3.2 is vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
https://github.com/python-pillow/Pillow/commit/9e08eb8f78fdfd2f476e1b20b7cf38683754866b
https://pillow.readthedocs.io/en/stable/releasenotes/8.3.2.html
Latest version: 11.0.0
Python Imaging Library (Fork)
The package pillow from 0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function. See CVE-2021-23437.
MISC:https://github.com/python-pillow/Pillow/commit/9e08eb8f78fdfd2f476e1b20b7cf38683754866b: https://github.com/python-pillow/Pillow/commit/9e08eb8f78fdfd2f476e1b20b7cf38683754866b
MISC:https://pillow.readthedocs.io/en/stable/releasenotes/8.3.2.html: https://pillow.readthedocs.io/en/stable/releasenotes/8.3.2.html
MISC:https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1319443: https://snyk.io/vuln/SNYK-PYTHON-PILLOW-1319443
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application