Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfh3-3jmp-rvhc

Опубликовано: 11 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.6

Описание

Pillow affected by out-of-bounds write when loading PSD images

Impact

An out-of-bounds write may be triggered when loading a specially crafted PSD image. Pillow >= 10.3.0 users are affected.

Patches

Pillow 12.1.1 will be released shortly with a fix for this.

Workarounds

Image.open() has a formats parameter that can be used to prevent PSD images from being opened.

References

Pillow 12.1.1 will add release notes at https://pillow.readthedocs.io/en/stable/releasenotes/index.html

Пакеты

Наименование

pillow

pip
Затронутые версииВерсия исправления

>= 10.3.0, < 12.1.1

12.1.1

EPSS

Процентиль: 29%
0.00367
Низкий

8.6 High

CVSS4

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.5
ubuntu
6 месяцев назад

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

CVSS3: 7.3
redhat
6 месяцев назад

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

CVSS3: 7.5
nvd
6 месяцев назад

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

CVSS3: 7.5
debian
6 месяцев назад

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an o ...

suse-cvrf
4 месяца назад

Security update for python-Pillow

EPSS

Процентиль: 29%
0.00367
Низкий

8.6 High

CVSS4

Дефекты

CWE-787