| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
To report sensitive vulnerability information, report it privately on GitHub.
If you cannot use GitHub, use the Tidelift security contact. Tidelift will coordinate the fix and disclosure.
DO NOT report sensitive vulnerability information in public.
Pillow's primary attack surface is parsing untrusted image data. A full STRIDE threat model covering spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege is maintained in the Security handbook page.
Key risks to be aware of when using Pillow to process untrusted images:
| Back | FazBrowse Home | New Git URL |