Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 04 Mar 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bigcat88 pillow-heif
|
|
| CPEs | cpe:2.3:a:bigcat88:pillow-heif:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Bigcat88 pillow-heif
|
|
| Metrics |
cvssV3_1
|
Tue, 03 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bigcat88
Bigcat88 pillow Heif |
|
| Vendors & Products |
Bigcat88
Bigcat88 pillow Heif |
Fri, 27 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds read. This can lead to information disclosure (server heap memory leaking into encoded images) or denial of service (process crash). No special configuration is required — this triggers under default settings. Version 1.3.0 fixes the issue. | |
| Title | pillow_heif Has Integer Overflow in Encode Path Buffer Validation that Leads to Heap Out-of-Bounds Read | |
| Weaknesses | CWE-125 CWE-190 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-03T20:25:30.145Z
Reserved: 2026-02-25T15:28:40.651Z
Link: CVE-2026-28231
Updated: 2026-03-03T20:25:27.680Z
Status : Analyzed
Published: 2026-02-27T20:21:40.697
Modified: 2026-03-04T15:55:20.027
Link: CVE-2026-28231
No data.
OpenCVE Enrichment
Updated: 2026-04-17T14:00:15Z