Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Security: python-pillow/Pillow

.github/SECURITY.md

Security policy

Reporting a vulnerability

To report sensitive vulnerability information, report it privately on GitHub.

If you cannot use GitHub, use the Tidelift security contact. Tidelift will coordinate the fix and disclosure.

DO NOT report sensitive vulnerability information in public.

Threat model

Pillow's primary attack surface is parsing untrusted image data. A full STRIDE threat model covering spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege is maintained in the Security handbook page.

Key risks to be aware of when using Pillow to process untrusted images:

  • Decompression bombs — do not set Image.MAX_IMAGE_PIXELS = None in production.
  • EPS files invoke Ghostscript — block EPS input at the application layer unless strictly required.
  • ImageMath.unsafe_eval() — never pass user-controlled strings to this function; use lambda_eval instead.
  • C extension memory safety — keep Pillow and its bundled C libraries (libjpeg, libpng, libtiff, libwebp, etc.) up to date.
  • Sandboxing — for high-risk deployments, run image processing in a sandboxed subprocess.
Learn more about advisories related to python-pillow/Pillow in the GitHub Advisory Database
Morty Proxy This is a proxified and sanitized view of the page, visit original site.