๐Ÿ” CVE Alert

CVE-2026-42311

UNKNOWN 0.0

Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

CWE CWE-190 CWE-787
Vendor python-pillow
Product pillow
Published May 9, 2026
Stay Ahead of the Next One

Get instant alerts for python-pillow pillow

Be the first to know when new unknown vulnerabilities affecting python-pillow pillow are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

python-pillow / Pillow
>= 10.3.0, < 12.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr github.com: https://github.com/python-pillow/Pillow/pull/9520 github.com: https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea github.com: https://github.com/python-pillow/Pillow/releases/tag/12.2.0