PT-2026-37200 · Pypi+2 · Pillow+2

·

CVE-2026-42311

·

Published

2026-05-04

·

Updated

2026-07-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pillow versions 10.3.0 through 12.1.x
Description Processing a malicious PSD file can lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This occurs because bounds checks for tile extents in PSD image decoding and encoding used types susceptible to integer overflow. A PSD image with specifically crafted tile dimensions could cause values to wrap around, bypassing the checks and triggering an out-of-bounds write in the src/decode.c and src/encode.c files.
Recommendations Update to version 12.2.0.

Exploit

Fix

Memory Corruption

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PILLOW-2026-42311
CLEANSTART-2026-EN66750
CLEANSTART-2026-FG72002
CLEANSTART-2026-RF67070
CVE-2026-42311
ECHO-4895-DA6A-8B1F
GHSA-PWV6-VV43-88GR
OESA-2026-2428
OESA-2026-2429
OPENSUSE-SU-2026:11261-1
OPENSUSE-SU-2026:21296-1
PYSEC-2026-2252
SUSE-SU-2026:22626-1
USN-8399-1

Affected Products

Linuxmint
Pillow
Ubuntu