Open Source Security mailing list@oss_securityPatch
CVE-2026-25990 is an OOB write in Pillow triggered by crafted PSD files, fixed in version 12.1.1.
Yarden Porat(Yarpo)@PwrtYrdnDisclosure
A new CVE, CVE-2026-25990, has been identified as an out-of-bounds write in the Pillow library. The advisory and details are available via the provided GitHub link.
CVE@CVEnewDisclosure
The advisory discloses CVE-2026-25990, an out-of-bounds write vulnerability in Pillow triggered by malformed PSD files, affecting versions 10.3.0 to before 12.1.1.
Ferramentas Linux@Cezar_H_LinuxPatch
The tweet announces that CVE-2026-25990 has been patched in the python-pillow library for Fedora 42 users.
PulsePatch.io@pulsepatchioPatch
The tweet highlights CVE‑2026‑25990, an out‑of‑bounds write in Pillow that could cause crashes, and recommends upgrading to version 12.1.1.
cvereports@_cvereportsDisclosure
High‑severity OOB write vulnerability identified in Pillow’s PSD handler; details disclosed but no PoC, exploit, patch, or active exploitation reported.