CVE-2021-25287
Python vulnerability analysis and mitigation

Overview

An out-of-bounds read vulnerability (CVE-2021-25287) was discovered in Pillow before version 8.2.0. The vulnerability specifically affects the J2kDecode functionality in the j2ku_graya_la component. This security issue was identified and disclosed in early 2021, affecting the Python Imaging Library (Pillow) software (MITRE CVE, NVD).

Technical details

The vulnerability occurs in the JPEG2000 decoder implementation where for J2k images with multiple bands, it's legal to have different widths for each band (e.g., 1 byte for L, 4 bytes for A). The issue dates back to Pillow 2.4.0 and could lead to an out-of-bounds read condition. The vulnerability has been assigned a CVSS v3.1 base score of 9.1 (Critical) with attack vector: Network, attack complexity: Low, privileges required: None, user interaction: None, scope: Unchanged, confidentiality: High, integrity: None, and availability: High (Ubuntu Security).

Impact

The vulnerability could potentially lead to unauthorized access to memory contents and denial of service conditions. When exploited, the out-of-bounds read vulnerability could allow attackers to read sensitive information from memory locations that should be inaccessible, potentially exposing confidential data (NVD).

Exploitability

The vulnerability is remotely exploitable and requires no user interaction or special privileges. It can be triggered through specially crafted JPEG2000 images with specific band configurations (Ubuntu Security).

Mitigation and workarounds

The vulnerability has been fixed in Pillow version 8.2.0. Users are advised to upgrade to this version or later. Multiple Linux distributions have released security updates to address this vulnerability, including Ubuntu, Fedora, and Gentoo. For systems that cannot be immediately updated, there are no known workarounds (Gentoo Security, Pillow Docs).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84366HIGH7.4
  • Python logoPython
  • python3.9
NoYesSep 01, 2026
CVE-2026-53720MEDIUM5.1
  • Python logoPython
  • pymonocypher
NoYesSep 03, 2026
CVE-2026-84311MEDIUM4.8
  • Python logoPython
  • pypdf
NoYesSep 01, 2026
CVE-2026-84310MEDIUM4.8
  • Python logoPython
  • pypdf
NoYesSep 01, 2026
GHSA-wwv5-g3v4-889xLOW2.3
  • Python logoPython
  • tornado
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management