CVE-2026-28231Disclosure(bigcat88 / pillow-heif)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds read. This can lead to information disclosure (server heap memory leaking into encoded images) or denial of service (process crash). No special configuration is required — this triggers under default settings. Version 1.3.0 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pillow-heif

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
pillow-heif

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-28: 2Technical Details · 2026-02-28: 202-28
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28231 Heap Out-of-Bounds Read Vulnerability in pillow_heif Python Library Before 1.3.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28231

    Post summary

    The text discloses a heap out‑of‑bounds read vulnerability affecting pillow_heif Python library versions older than 1.3.0.

    0001056
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28231 pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation o… https://www.cve.org/CVERecord?id=CVE-2026-28231

    Post summary

    The text announces CVE-2026-28231, describing an integer overflow in pillow_heif’s encode path, but provides no PoC, exploit, or patch details.

    00000139
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbigcat88pillow-heif-python-

Explore more