[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2022-22815":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":28,"aliases":29,"duplicate_of":9,"upstream":33,"downstream":34,"duplicates":59,"related":60,"reserved_at":9,"published_at":65,"modified_at":66,"state":67,"summary":68,"references_raw":77,"kevs":138,"epss":139,"epss_history":142,"metrics":404,"affected":419},"CVE-2022-22815","path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-665","Improper Initialization","The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.","weakness","Draft","Class","Medium",[20,24],{"id":21,"name":22,"techniques":23},"CAPEC-26","Leveraging Race Conditions",[],{"id":25,"name":26,"techniques":27},"CAPEC-29","Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions",[],[],[30,31,32],"GHSA-pw3c-h7wp-cvhx","BIT-pillow-2022-22815","PYSEC-2022-8",[],[35,37,39,41,43,45,47,49,51,53,55,57],{"_key":36},"ALPINE-CVE-2022-22815",{"_key":38},"SUSE-SU-2022:1729-1",{"_key":40},"SUSE-SU-2024:1673-2",{"_key":42},"UBUNTU-CVE-2022-22815",{"_key":44},"SUSE-SU-2024:1673-1",{"_key":46},"DLA-2893-1",{"_key":48},"DSA-5053-1",{"_key":50},"RHSA-2022:0643",{"_key":52},"MGASA-2022-0166",{"_key":54},"USN-5227-1",{"_key":56},"DEBIAN-CVE-2022-22815",{"_key":58},"USN-5227-2",[],[61,62,63,64],{"_key":38},{"_key":40},{"_key":44},{"_key":52},"2022-01-07T00:00:00.000Z","2024-08-03T03:21:49.146Z","Modified",{"cisa_kev":69,"cisa_ransomware":69,"cisa_vendor":9,"epss_severity":70,"epss_score":71,"severity":72,"severity_score":73,"severity_version":74,"severity_source":75,"severity_vector":76,"severity_status":67},false,"low",0.00095,"medium",6.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",[78,86,91,96,100,104,109,113,117,121,125,129,134],{"url":79,"sources":80,"tags":83},"https://pillow.readthedocs.io/en/stable/releasenotes/9.0.0.html#fixed-imagepath-path-array-handling",[81,75,82],"cve.org","osv_pypi",[84,85],"Vendor Advisory","WEB",{"url":87,"sources":88,"tags":89},"https://github.com/python-pillow/Pillow/blob/c5d9223a8b5e9295d15b5a9b1ef1dae44c8499f3/src/path.c#L331",[81,75,82],[90,85],"Third Party Advisory",{"url":92,"sources":93,"tags":94},"https://lists.debian.org/debian-lts-announce/2022/01/msg00018.html",[81,75,82],[95,90,85],"Mailing List",{"url":97,"sources":98,"tags":99},"https://www.debian.org/security/2022/dsa-5053",[81,75,82],[84,90,85],{"url":101,"sources":102,"tags":103},"https://security.gentoo.org/glsa/202211-10",[81,75],[84,90],{"url":105,"sources":106,"tags":107},"https://nvd.nist.gov/vuln/detail/CVE-2022-22815",[82],[108],"Advisory",{"url":110,"sources":111,"tags":112},"https://github.com/python-pillow/Pillow/pull/5920",[82],[85],{"url":114,"sources":115,"tags":116},"https://github.com/python-pillow/Pillow/commit/1e092419b6806495c683043ab3feb6ce264f3b9c",[82],[85],{"url":118,"sources":119,"tags":120},"https://github.com/python-pillow/Pillow/commit/c48271ab354db49cdbd740bc45e13be4f0f7993c",[82],[85],{"url":122,"sources":123,"tags":124},"https://github.com/advisories/GHSA-pw3c-h7wp-cvhx",[82],[108],{"url":126,"sources":127,"tags":128},"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2022-8.yaml",[82],[85],{"url":130,"sources":131,"tags":132},"https://github.com/python-pillow/Pillow",[82],[133],"PACKAGE",{"url":135,"sources":136,"tags":137},"https://github.com/python-pillow/Pillow/blob/e8ab5640774716c5486d3cb05167f74f742ad6ef/CHANGES.rst?plain=1#L1187",[82],[85],[],{"date":140,"score":71,"percentile":141},"2026-06-04",0.26312,[143,146,149,152,155,158,161,164,167,170,173,176,179,182,185,189,192,195,198,200,203,206,209,212,215,218,221,224,227,230,232,235,238,240,243,245,248,251,254,257,260,263,266,269,272,274,277,280,283,286,289,292,295,298,301,303,306,309,312,315,318,321,324,327,330,332,335,338,341,343,346,349,352,355,358,361,364,367,370,373,376,378,381,384,387,390,393,396,399,401],{"date":144,"score":71,"percentile":145},"2025-11-04",0.27203,{"date":147,"score":71,"percentile":148},"2025-11-05",0.27189,{"date":150,"score":71,"percentile":151},"2025-11-06",0.272,{"date":153,"score":71,"percentile":154},"2025-11-07",0.27199,{"date":156,"score":71,"percentile":157},"2025-11-08",0.27194,{"date":159,"score":71,"percentile":160},"2025-11-09",0.2715,{"date":162,"score":71,"percentile":163},"2025-11-10",0.27115,{"date":165,"score":71,"percentile":166},"2025-11-11",0.2714,{"date":168,"score":71,"percentile":169},"2025-11-12",0.27184,{"date":171,"score":71,"percentile":172},"2025-11-13",0.27191,{"date":174,"score":71,"percentile":175},"2025-11-14",0.27177,{"date":177,"score":71,"percentile":178},"2025-11-15",0.27164,{"date":180,"score":71,"percentile":181},"2025-11-16",0.2712,{"date":183,"score":71,"percentile":184},"2025-11-17",0.27089,{"date":186,"score":187,"percentile":188},"2025-11-18",0.00945,0.74326,{"date":190,"score":187,"percentile":191},"2025-11-19",0.74334,{"date":193,"score":187,"percentile":194},"2025-11-20",0.74343,{"date":196,"score":71,"percentile":197},"2025-11-21",0.27094,{"date":199,"score":71,"percentile":197},"2025-11-22",{"date":201,"score":71,"percentile":202},"2025-11-23",0.27053,{"date":204,"score":71,"percentile":205},"2025-11-24",0.27023,{"date":207,"score":71,"percentile":208},"2025-11-25",0.27014,{"date":210,"score":71,"percentile":211},"2025-11-26",0.27004,{"date":213,"score":71,"percentile":214},"2025-11-27",0.27012,{"date":216,"score":71,"percentile":217},"2025-11-28",0.26982,{"date":219,"score":71,"percentile":220},"2025-11-29",0.26966,{"date":222,"score":71,"percentile":223},"2025-11-30",0.26941,{"date":225,"score":71,"percentile":226},"2025-12-01",0.26995,{"date":228,"score":71,"percentile":229},"2025-12-02",0.27018,{"date":231,"score":71,"percentile":205},"2025-12-03",{"date":233,"score":71,"percentile":234},"2025-12-04",0.26956,{"date":236,"score":71,"percentile":237},"2025-12-05",0.26994,{"date":239,"score":71,"percentile":237},"2025-12-06",{"date":241,"score":71,"percentile":242},"2025-12-07",0.26962,{"date":244,"score":71,"percentile":220},"2025-12-08",{"date":246,"score":71,"percentile":247},"2025-12-09",0.27022,{"date":249,"score":71,"percentile":250},"2025-12-10",0.27097,{"date":252,"score":71,"percentile":253},"2025-12-11",0.27129,{"date":255,"score":71,"percentile":256},"2025-12-12",0.27141,{"date":258,"score":71,"percentile":259},"2025-12-13",0.27139,{"date":261,"score":71,"percentile":262},"2025-12-14",0.27105,{"date":264,"score":71,"percentile":265},"2025-12-15",0.27076,{"date":267,"score":71,"percentile":268},"2025-12-16",0.27088,{"date":270,"score":71,"percentile":271},"2025-12-17",0.27147,{"date":273,"score":71,"percentile":151},"2025-12-18",{"date":275,"score":71,"percentile":276},"2025-12-19",0.27215,{"date":278,"score":71,"percentile":279},"2025-12-20",0.27183,{"date":281,"score":71,"percentile":282},"2025-12-21",0.27146,{"date":284,"score":71,"percentile":285},"2025-12-22",0.27118,{"date":287,"score":71,"percentile":288},"2025-12-23",0.27083,{"date":290,"score":71,"percentile":291},"2025-12-24",0.27095,{"date":293,"score":71,"percentile":294},"2025-12-25",0.2717,{"date":296,"score":71,"percentile":297},"2025-12-26",0.27163,{"date":299,"score":71,"percentile":300},"2025-12-27",0.27154,{"date":302,"score":71,"percentile":265},"2025-12-28",{"date":304,"score":71,"percentile":305},"2025-12-29",0.27047,{"date":307,"score":71,"percentile":308},"2025-12-30",0.27044,{"date":310,"score":71,"percentile":311},"2025-12-31",0.2711,{"date":313,"score":71,"percentile":314},"2026-01-01",0.27221,{"date":316,"score":71,"percentile":317},"2026-01-02",0.2722,{"date":319,"score":71,"percentile":320},"2026-01-03",0.27201,{"date":322,"score":71,"percentile":323},"2026-01-04",0.27098,{"date":325,"score":71,"percentile":326},"2026-01-05",0.27087,{"date":328,"score":71,"percentile":329},"2026-01-06",0.27091,{"date":331,"score":71,"percentile":181},"2026-01-07",{"date":333,"score":71,"percentile":334},"2026-01-08",0.27167,{"date":336,"score":71,"percentile":337},"2026-01-09",0.27153,{"date":339,"score":71,"percentile":340},"2026-01-10",0.27124,{"date":342,"score":71,"percentile":262},"2026-01-11",{"date":344,"score":71,"percentile":345},"2026-01-12",0.27061,{"date":347,"score":71,"percentile":348},"2026-01-13",0.27042,{"date":350,"score":71,"percentile":351},"2026-01-14",0.27084,{"date":353,"score":71,"percentile":354},"2026-01-15",0.27081,{"date":356,"score":71,"percentile":357},"2026-01-16",0.27113,{"date":359,"score":71,"percentile":360},"2026-01-17",0.27119,{"date":362,"score":71,"percentile":363},"2026-01-18",0.27068,{"date":365,"score":71,"percentile":366},"2026-01-19",0.27026,{"date":368,"score":71,"percentile":369},"2026-01-20",0.27008,{"date":371,"score":71,"percentile":372},"2026-01-21",0.26955,{"date":374,"score":71,"percentile":375},"2026-01-22",0.26932,{"date":377,"score":71,"percentile":211},"2026-01-23",{"date":379,"score":71,"percentile":380},"2026-01-24",0.27001,{"date":382,"score":71,"percentile":383},"2026-01-25",0.26926,{"date":385,"score":71,"percentile":386},"2026-01-26",0.26842,{"date":388,"score":71,"percentile":389},"2026-01-27",0.26823,{"date":391,"score":71,"percentile":392},"2026-01-28",0.26813,{"date":394,"score":71,"percentile":395},"2026-01-29",0.26766,{"date":397,"score":71,"percentile":398},"2026-01-30",0.26761,{"date":400,"score":71,"percentile":398},"2026-01-31",{"date":402,"score":71,"percentile":403},"2026-02-01",0.26817,[405,414],{"source":75,"cvss_v2_0":406,"cvss_v3_0":9,"cvss_v3_1":411,"cvss_v4_0":9},{"baseScore":407,"baseSeverity":9,"vectorString":408,"impactScore":409,"exploitabilityScore":410},6.4,"AV:N/AC:L/Au:N/C:N/I:P/A:P",4.9,10,{"baseScore":73,"baseSeverity":412,"vectorString":76,"impactScore":413,"exploitabilityScore":410},"MEDIUM",4.2,{"source":82,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":415,"cvss_v4_0":416},{"baseScore":73,"baseSeverity":9,"vectorString":76,"impactScore":413,"exploitabilityScore":410},{"baseScore":417,"baseSeverity":9,"vectorString":418,"impactScore":9,"exploitabilityScore":9},6.9,"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",[420,433,444],{"ecosystem":9,"name":421,"vendor":422,"product":423,"cpe_part":424,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":425},"debian linux","debian","debian_linux","o",[426,429,431],{"version":427,"is_range":69,"range_type":428,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"9.0","cpe",{"version":430,"is_range":69,"range_type":428,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.0",{"version":432,"is_range":69,"range_type":428,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0",{"ecosystem":434,"name":435,"vendor":434,"product":435,"cpe_part":9,"purl_type":436,"purl_namespace":9,"purl_name":435,"source":9,"versions":437},"PyPI","pillow","pypi",[438],{"version":439,"is_range":440,"range_type":441,"version_start":9,"version_start_type":9,"version_end":442,"version_end_type":443,"fixed_in":9},"lt9_0_0",true,"ecosystem","9.0.0","excluding",{"ecosystem":9,"name":435,"vendor":445,"product":435,"cpe_part":446,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":447},"python","a",[448],{"version":449,"is_range":440,"range_type":428,"version_start":9,"version_start_type":9,"version_end":442,"version_end_type":443,"fixed_in":9},"lt9.0.0"]