Skip to content

Is Pillow affected by WebP vulnerability? #7626

@afk42

Description

@afk42

Being aware that CVE-2023-4863 was already fixed in Pillow 10.0.1 and as I'm unable to update to that version at the moment, I want to understand if Pillow really uses any of the functionality where the issue resides or if the CVE can be whitelisted since use of this vulnerable library is excluded by the functional design of Pillow.

Thank you

What are your OS, Python and Pillow versions?

  • OS:
  • Python:
  • Pillow: < 10.0.1

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions