{"schema_version":"1.7.5","id":"PYSEC-2026-1794","published":"2026-07-07T11:45:24.102852Z","modified":"2026-07-07T17:56:20.858779255Z","aliases":["A-299477569","ASB-A-299477569","CVE-2023-4863","CVE-2023-5129","GHSA-j7hp-h8jx-5ppr","RUSTSEC-2023-0060","RUSTSEC-2023-0061"],"summary":"libwebp: OOB write in BuildHuffmanTable","details":"Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.","affected":[{"package":{"name":"pillow","ecosystem":"PyPI","purl":"pkg:pypi/pillow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.0.1"}]}],"versions":["1.0","1.1","1.2","1.3","1.4","1.5","1.6","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.7.5","1.7.6","1.7.7","1.7.8","10.0.0","2.0.0","2.1.0","2.2.0","2.2.1","2.2.2","2.3.0","2.3.1","2.3.2","2.4.0","2.5.0","2.5.1","2.5.2","2.5.3","2.6.0","2.6.1","2.6.2","2.7.0","2.8.0","2.8.1","2.8.2","2.9.0","3.0.0","3.1.0","3.1.0.rc1","3.1.0rc1","3.1.1","3.1.2","3.2.0","3.3.0","3.3.1","3.3.2","3.3.3","3.4.0","3.4.1","3.4.2","4.0.0","4.1.0","4.1.1","4.2.0","4.2.1","4.3.0","5.0.0","5.1.0","5.2.0","5.3.0","5.4.0","5.4.0.dev0","5.4.1","6.0.0","6.1.0","6.2.0","6.2.1","6.2.2","7.0.0","7.1.0","7.1.1","7.1.2","7.2.0","8.0.0","8.0.1","8.1.0","8.1.1","8.1.2","8.2.0","8.3.0","8.3.1","8.3.2","8.4.0","9.0.0","9.0.1","9.1.0","9.1.1","9.2.0","9.3.0","9.4.0","9.5.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/pillow/PYSEC-2026-1794.yaml"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4863"},{"type":"WEB","url":"https://github.com/qnighy/libwebp-sys2-rs/pull/21"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/7395"},{"type":"WEB","url":"https://github.com/jaredforth/webp/pull/30"},{"type":"WEB","url":"https://github.com/electron/electron/pull/39823"},{"type":"WEB","url":"https://github.com/electron/electron/pull/39825"},{"type":"WEB","url":"https://github.com/electron/electron/pull/39826"},{"type":"WEB","url":"https://github.com/electron/electron/pull/39827"},{"type":"WEB","url":"https://github.com/electron/electron/pull/39828"},{"type":"WEB","url":"https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17a"},{"type":"WEB","url":"https://github.com/qnighy/libwebp-sys2-rs/commit/4560c473a76ec8bd8c650f19ddf9d7a44f719f8b"},{"type":"WEB","url":"https://github.com/jaredforth/webp/commit/9d4c56e63abecc777df71c702503c3eaabd7dcbc"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202401-10"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202309-05"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2023-4863"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0061.html"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0060.html"},{"type":"WEB","url":"https://pillow.readthedocs.io/en/stable/releasenotes/10.0.1.html#security"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=37478403"},{"type":"WEB","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863"},{"type":"WEB","url":"https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230929-0011"},{"type":"WEB","url":"https://sethmlarson.dev/security-developer-in-residence-weekly-report-16"},{"type":"WEB","url":"https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863"},{"type":"WEB","url":"https://www.bentley.com/advisories/be-2023-0001"},{"type":"WEB","url":"https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks"},{"type":"WEB","url":"https://www.debian.org/security/2023/dsa-5496"},{"type":"WEB","url":"https://www.debian.org/security/2023/dsa-5497"},{"type":"WEB","url":"https://www.debian.org/security/2023/dsa-5498"},{"type":"WEB","url":"https://www.mozilla.org/en-US/security/advisories/mfsa2023-40"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/zero-day-webp-vulnerability-cve-2023-4863"},{"type":"WEB","url":"https://blog.isosceles.com/the-webp-0day"},{"type":"WEB","url":"https://bugzilla.suse.com/show_bug.cgi?id=1215231"},{"type":"WEB","url":"https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html"},{"type":"WEB","url":"https://crbug.com/1479274"},{"type":"WEB","url":"https://en.bandisoft.com/honeyview/history"},{"type":"WEB","url":"https://github.com/ImageMagick/ImageMagick/discussions/6664"},{"type":"WEB","url":"https://github.com/dlemstra/Magick.NET/releases/tag/13.3.0"},{"type":"PACKAGE","url":"https://github.com/webmproject/libwebp"},{"type":"WEB","url":"https://github.com/webmproject/libwebp/releases/tag/v1.3.2"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/09/msg00015.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/09/msg00016.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/09/msg00017.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U645"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/21/4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/22/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/22/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/22/4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/22/5"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/22/6"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/22/7"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/22/8"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/26/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/26/7"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/28/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/28/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/28/4"},{"type":"PACKAGE","url":"https://pypi.org/project/pillow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-j7hp-h8jx-5ppr"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}