{"schema_version":"1.7.5","id":"GHSA-cfh3-3jmp-rvhc","published":"2026-02-11T14:22:50Z","modified":"2026-07-13T07:26:49.514806069Z","aliases":["BIT-pillow-2026-25990","CVE-2026-25990","PYSEC-2026-2249"],"related":["CGA-w7gh-42x2-jfqf"],"summary":"Pillow affected by out-of-bounds write when loading PSD images","details":"### Impact\nAn out-of-bounds write may be triggered when loading a specially crafted PSD image. Pillow >= 10.3.0 users are affected.\n\n### Patches\nPillow 12.1.1 will be released shortly with a fix for this.\n\n### Workarounds\n`Image.open()` has a `formats` parameter that can be used to prevent PSD images from being opened.\n\n### References\nPillow 12.1.1 will add release notes at https://pillow.readthedocs.io/en/stable/releasenotes/index.html","affected":[{"package":{"name":"pillow","ecosystem":"PyPI","purl":"pkg:pypi/pillow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.3.0"},{"fixed":"12.1.1"}]}],"versions":["10.3.0","10.4.0","11.0.0","11.1.0","11.2.1","11.3.0","12.0.0","12.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-cfh3-3jmp-rvhc/GHSA-cfh3-3jmp-rvhc.json"}}],"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25990"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/pull/9427"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/54ba4db542ad3c7b918812a4e2d69c27735a3199"},{"type":"WEB","url":"https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa"},{"type":"PACKAGE","url":"https://github.com/python-pillow/Pillow"},{"type":"WEB","url":"https://pillow.readthedocs.io/en/stable/releasenotes/12.1.1.html"}],"database_specific":{"cwe_ids":["CWE-787"],"github_reviewed":true,"github_reviewed_at":"2026-02-11T14:22:50Z","nvd_published_at":"2026-02-11T21:16:20Z","severity":"HIGH"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}