pypi:pillowThis dossier links the stable identity pypi:pillow to 9 exact observed versions across 14 public repositories.
A package identity or provider interface in published code does not prove configuration, an account, procurement, data transfer or an API call.
ecosystem:name + exact version + evidence pathPublication age and licenses come from deps.dev metadata. They are context—not a maintenance, legal or portability verdict.
01 Apr 202401 Jul 202402 Jan 202512 Apr 202501 Jul 202515 Oct 202502 Jan 202611 Feb 202601 Jul 2026sh/digitalhub-sh/landesprogramm-offene-innovationen/ki-bauleitplaene/smartplanai-anwendung2 Occurrencesuba-ki-lab/strahlenexposition2 Occurrencesenergieautarkes-wohnquartier/backend1 Occurrenceiqsh/collaboration-online-board/ai1 Occurrencesh/diwish/splitbot/kosmo/llm-service1 Occurrenceuba-ki-lab/coding-agent-usage-simulation1 Occurrenceuba-ki-lab/density-maps1 Occurrenceuba-ki-lab/gsa-extraction1 Occurrenceuba-ki-lab/llm-questionnaire-benchmarking-framework1 Occurrenceuba-ki-lab/llm-testframework1 Occurrenceuba-ki-lab/objection-management1 Occurrenceuba-ki-lab/photovoltaic_systems1 Occurrenceuba-ki-lab/ressource-efficient-computer-vision1 Occurrenceuba-ki-lab/retrieval-evaluation1 Occurrenceiqsh/collaboration-online-board/aiSPDX_v2.0.0.ymluba-ki-lab/coding-agent-usage-simulationuv.lockuba-ki-lab/density-mapsuv.lockenergieautarkes-wohnquartier/backendpoetry.lockuba-ki-lab/gsa-extractionuv.lockuba-ki-lab/llm-questionnaire-benchmarking-frameworkuv.locksh/diwish/splitbot/kosmo/llm-serviceuv.lockuba-ki-lab/llm-testframeworkuv.lockuba-ki-lab/objection-managementuv.lockuba-ki-lab/photovoltaic_systemssbom.jsonuba-ki-lab/ressource-efficient-computer-visionuv.lockuba-ki-lab/retrieval-evaluationuv.locksh/digitalhub-sh/landesprogramm-offene-innovationen/ki-bauleitplaene/smartplanai-anwendungblp_streamlit_pipeline/src/ext/streamlit-draw-image-mask/poetry.locksh/digitalhub-sh/landesprogramm-offene-innovationen/ki-bauleitplaene/smartplanai-anwendungpoetry.lockuba-ki-lab/strahlenexpositionpoetry.lockuba-ki-lab/strahlenexpositionsbom.jsonPillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
22 Jul 2026Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
22 Jul 2026Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
22 Jul 2026Pillow has a heap buffer overflow with nested list coordinates
13 Jul 2026Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
23 Jul 2026Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
22 Jul 2026Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
22 Jul 2026Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
22 Jul 2026Pillow affected by out-of-bounds write when loading PSD images
13 Jul 2026Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
23 Jul 2026Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
23 Jul 2026Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
22 Jul 2026Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
22 Jul 2026Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
13 Jul 2026Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
13 Jul 2026Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
23 Jul 2026FITS GZIP decompression bomb in Pillow
13 Jul 2026Pillow has an integer overflow when processing fonts
09 Jun 2026Pillow vulnerability can cause write buffer overflow on BCn encoding
04 Feb 2026Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
22 Jul 2026Only exact npm and PyPI tuples are enriched. Reported SPDX expressions are metadata; no compatibility, obligation or legal conclusion is inferred.
Retrieval, parsing, matching and publishing use no generative AI model.i6eal (2026): pillow — exact AI dependency evidence dossier, data state 13 Aug 2026. https://i6eal.de/en/tools/ki-abhaengigkeitsatlas/paket/pillow-834347dd/
We build source-backed data products with stable identities, reproducible joins and boundaries that remain visible.
These tools complement the current result.