pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds read. This can lead to information disclosure (server heap memory leaking into encoded images) or denial of service (process crash). No special configuration is required — this triggers under default settings. Version 1.3.0 fixes the issue.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 04 Mar 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Bigcat88 pillow-heif
CPEs cpe:2.3:a:bigcat88:pillow-heif:*:*:*:*:*:python:*:*
Vendors & Products Bigcat88 pillow-heif
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Tue, 03 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Bigcat88
Bigcat88 pillow Heif
Vendors & Products Bigcat88
Bigcat88 pillow Heif

Fri, 27 Feb 2026 20:30:00 +0000

Type Values Removed Values Added
Description pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds read. This can lead to information disclosure (server heap memory leaking into encoded images) or denial of service (process crash). No special configuration is required — this triggers under default settings. Version 1.3.0 fixes the issue.
Title pillow_heif Has Integer Overflow in Encode Path Buffer Validation that Leads to Heap Out-of-Bounds Read
Weaknesses CWE-125
CWE-190
References
Metrics cvssV4_0

{'score': 5.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-03T20:25:30.145Z

Reserved: 2026-02-25T15:28:40.651Z

Link: CVE-2026-28231

cve-icon Vulnrichment

Updated: 2026-03-03T20:25:27.680Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-27T20:21:40.697

Modified: 2026-03-04T15:55:20.027

Link: CVE-2026-28231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-02T12:05:01Z

Weaknesses