Vulnerability Details CVE-2026-25990
Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.6%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-25990
-
cpe:2.3:a:python:pillow:10.3.0
-
cpe:2.3:a:python:pillow:10.4.0
-
cpe:2.3:a:python:pillow:11.0.0
-
cpe:2.3:a:python:pillow:11.1.0
-
cpe:2.3:a:python:pillow:11.2.1
-
cpe:2.3:a:python:pillow:11.3.0
-
cpe:2.3:a:python:pillow:12.0.0