CVE-2026-25990Disclosure(python / pillow)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch python pillow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pillow

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 2 mentions (2026-02-11); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
pillow

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-11: 2Mentions · 2026-02-12: 1Mentions · 2026-02-15: 1Mentions · 2026-02-17: 1Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-15: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-02-11: 2Technical Details · 2026-02-12: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-17: 102-1102-1202-1502-1703-03
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-112
Disclosure2
2026-02-121
Disclosure1
2026-02-151
Patch1
2026-02-171
Patch1
2026-03-031
Patch1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-25990: Pillow: OOB write with invalid tile extents https://www.openwall.com/lists/oss-security/2026/02/12/1 Pillow is a fork of Python Imaging Library (PIL). An out-of-bounds write may be triggered when opening a specially crafted PSD image. This only affects Pillow >= 10.3.0. Fixed in 12.1.1.

    Post summary

    CVE-2026-25990 is an OOB write in Pillow triggered by crafted PSD files, fixed in version 12.1.1.

    0301451.4K
    4.4K followersView on X
  • Yarden Porat(Yarpo)@PwrtYrdn
    Disclosure

    CVE-2026-25990 - Out Of Bounds Write Cyata found on pillow library. BlogPost Soon... https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc

    Post summary

    A new CVE, CVE-2026-25990, has been identified as an out-of-bounds write in the Pillow library. The advisory and details are available via the provided GitHub link.

    01041289
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25990 Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerabilit… https://www.cve.org/CVERecord?id=CVE-2026-25990

    Post summary

    The advisory discloses CVE-2026-25990, an out-of-bounds write vulnerability in Pillow triggered by malformed PSD files, affecting versions 10.3.0 to before 12.1.1.

    00010450
    56.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ Critical Security Update for #Fedora 42 Users 🛡️ A high-severity vulnerability (CVE-2026-25990) has been patched in the python-pillow library, a core component for #Python image processing. Read more: 👉 https://tinyurl.com/yywffk8w #Security https://t.co/UpSDXS5QBM

    Post summary

    The tweet announces that CVE-2026-25990 has been patched in the python-pillow library for Fedora 42 users.

    0000051
    1.3K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Pillow, a popular Python imaging library, has an out-of-bounds write vulnerability (CVE-2026-25990) when loading PSD images. This could lead to crashes or data corruption. Update to 12.1.1. #Python #Pillow #infosec https://www.pulsepatch.io/posts/cve-2026-25990-pillow-out-of-bounds-write

    Post summary

    The tweet highlights CVE‑2026‑25990, an out‑of‑bounds write in Pillow that could cause crashes, and recommends upgrading to version 12.1.1.

    0000047
    1 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25990: Pillow Fight: Weaponizing Photoshop Files via OOB Writes A high-severity Out-of-Bounds Write vulnerability exists in Pillow, the de facto Python Imaging Library, specifically within its Photoshop Document (PSD) handler. The flaw arises... https://cvereports.com/reports/CVE-2026-25990

    Post summary

    High‑severity OOB write vulnerability identified in Pillow’s PSD handler; details disclosed but no PoC, exploit, patch, or active exploitation reported.

    0000032
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonpillow---

Explore more