CVE-2026-25990
Pillow has an out-of-bounds write when loading PSD images
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
5th
Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.
| CWE | CWE-787 |
| Vendor | python-pillow |
| Product | pillow |
| Published | Feb 11, 2026 |
| Last Updated | Apr 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for python-pillow pillow
Be the first to know when new unknown vulnerabilities affecting python-pillow pillow are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
python-pillow / Pillow
>= 10.3.0, < 12.1.1