Junglewise Threat Intelligence

CVE-2026-25990: python-pillow Pillow out-of-bounds write in PSD image loading

CVE-2026-25990 · Severity: high · CVSS 7.5 · Published 2026-02-11

Technologies: Python-Pillow Pillow. Vendors: PyPI.

Executive brief

Pillow, a widely used Python library for image processing, contains a vulnerability that can be triggered when processing Adobe Photoshop (PSD) files. An attacker could provide a specially crafted image file that, when opened by an application using Pillow, causes the program to crash or behave unexpectedly. This could lead to a denial-of-service condition, impacting the availability of services that automate image handling or thumbnail generation.

Technical details

An out-of-bounds (OOB) write vulnerability (CWE-787) exists in Pillow's PSD image decoding logic. The flaw is rooted in a failure to validate tile extents, specifically allowing negative x or y offsets during the decoding or encoding process. An attacker can exploit this by providing a malformed PSD file, which triggers a write outside the intended buffer when processed via `Image.open()`. This can result in a process crash (DoS) or potentially memory corruption. The issue is resolved in version 12.1.1 by implementing checks to ensure tile extents do not use negative offsets. A temporary workaround involves using the `formats` parameter in `Image.open()` to disable PSD support.

Affected products

  • python-pillow Pillow >= 10.3.0, < 12.1.1

Timeline

  • 2026-02-11: disclosed
  • 2026-02-11: patched: Fixed in version 12.1.1
  • 2026-02-11: advisory

References

Related threats