Launchpad.net

CVE 2021-23437

The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

See the CVE page on Mitre.org for more details.