CVE-2021-28678 | Pillow up to 8.1.x BLP Data BlpImagePlugin denial of service (Nessus ID 236661 / WID-SEC-2022-1835)
A vulnerability was found in Pillow up to 8.1.x. It has been classified as problematic. The affected element is the function BlpImagePlugin of the component BLP Data Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2021-28678. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.