Skip to content

[GHSA-5xmw-vc9v-4wf2] Pillow has a heap buffer overflow with nested list coordinates - #10210

Open
ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10210from
ranjiGT-GHSA-5xmw-vc9v-4wf2
Open

ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10210from
ranjiGT-GHSA-5xmw-vc9v-4wf2

Conversation

@ranjiGT

@ranjiGT ranjiGT commented Oct 7, 2026

Copy link
Copy Markdown

Updates

  • CVSS v3
  • References

Comments
Adds the upstream fix commit for this vulnerability.

The commit "Reject non-numeric elements inside list coords (#9526)" validates coordinate lists to contain exactly two numeric coordinates and is included in 12.2.0, the patched version already listed by this advisory.

@github

github commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Hi there @aclark4life! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

Copilot AI balanced review requested due to automatic review settings October 7, 2026 17:56
@github-actions
github-actions Bot changed the base branch from main to ranjiGT/advisory-improvement-10210 October 7, 2026 17:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The advisory remains valid JSON, and the added commit correctly fixes the vulnerability and is included in the listed patched release.

0 open findings

What changed in this PR

Updates the Pillow vulnerability advisory with current severity metadata and the upstream fix reference.

Changes:

  • Removes the CVSS v3 severity entry.
  • Adds the verified fixing commit included in Pillow 12.2.0.
File Description
GHSA-5xmw-vc9v-4wf2.json Updates severity metadata and references the upstream fix.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants