Out-of-Bounds Write Vulnerability in Python Imaging Library by Pillow
CVE-2026-25990

8.9HIGH

Key Information:

Status
Vendor
CVE Published:
11 February 2026

What is CVE-2026-25990?

The Pillow library, a widely-used imaging library for Python, is susceptible to an out-of-bounds write vulnerability when processing specially crafted PSD images. This could potentially allow attackers to execute arbitrary code or cause application crashes. This risk primarily affects versions from 10.3.0 up to just before 12.1.1. Users are advised to upgrade to version 12.1.1 or later to mitigate this issue. For further details, refer to the advisory and the commit log for a complete overview of the fixes implemented.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Pillow >= 10.3.0, < 12.1.1

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.