This is an informational KB regarding the CVE-2026-54058, a security vulnerability affecting the Pillow Python library. Security scanners and container scanning tools may flag this vulnerability in current versions of the Bitnami package for Apache Superset.
Tanzu App Catalog
The vulnerability has been successfully patched by the Pillow maintainers in release 12.3.0. However, the Bitnami Secure Image inherits this dependency directly from the upstream Apache Superset project.
As of the latest upstream release (Apache Superset 6.1.0), the project still strictly pins an older, vulnerable version of the Pillow library in its base requirements
Once the new version of the pillow (12.3.0 or above) is packaged in the upstream Apache Superset project the same will be picked up by the Bitnami package for Apache Superset.
This information has been updated in the Assessments view of the corresponding Container Image catalog section.