The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
{ "cpes": [ "cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*" ], "severity": "High" }