Out-of-Bounds Write Vulnerability in Python Imaging Library by Pillow
CVE-2026-25990
8.9HIGH
What is CVE-2026-25990?
The Pillow library, a widely-used imaging library for Python, is susceptible to an out-of-bounds write vulnerability when processing specially crafted PSD images. This could potentially allow attackers to execute arbitrary code or cause application crashes. This risk primarily affects versions from 10.3.0 up to just before 12.1.1. Users are advised to upgrade to version 12.1.1 or later to mitigate this issue. For further details, refer to the advisory and the commit log for a complete overview of the fixes implemented.
Affected Version(s)
Pillow >= 10.3.0, < 12.1.1
