Regular Expression Denial of Service (ReDoS)
CVE-2021-23437
7.5HIGH
What is CVE-2021-23437?
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
Affected Version(s)
Pillow 0
Pillow < 8.3.2