CVE-2026-27809Disclosure(psd-tools_project / psd-tools)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch psd-tools_project psd-tools systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row size), decode_rle() raises ValueError which propagated all the way to the user, crashing psd.composite() and psd-tools export. decompress() already had a fallback that replaces failed channels with black pixels when result is None, but it never triggered because the ValueError from decode_rle() was not caught. The fix in version 1.12.2 wraps the decode_rle() call in a try/except so the existing fallback handles the error gracefully.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190CWE-409CWE-617CWE-704CWE-755CWE-789

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • psd-tools

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
psd-tools

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-26: 2Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-26: 2Technical Details · 2026-03-03: 102-2603-03
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure2
2026-03-031
General1
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27809 (CVSS:6.8, CRITICAL) is Analyzed. psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file conta..https://nvd.nist.gov/vuln/detail/CVE-2026-27809 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-27809, noting its CVSS score and critical severity, but provides no further details on exploitation, patches, or PoC.

    0000026
    173 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27809: Death by Pixels: Unpacking CVE-2026-27809 in psd-tools A deep dive into a series of memory corruption and logic flaws within the `psd-tools` Python library. This vulnerability exploits the complex nature of Adobe's PSD format to trigge... https://cvereports.com/reports/CVE-2026-27809

    Post summary

    The article provides a technical analysis of CVE‑2026‑27809, outlining memory corruption and logic flaws in psd‑tools, but offers no PoC, exploit code, or patch information.

    0000031
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27809 psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. … https://www.cve.org/CVERecord?id=CVE-2026-27809

    Post summary

    The CVE‑2026‑27809 vulnerability in psd‑tools involves malformed RLE‑compressed image data, and version 1.12.2 is implied to address the issue.

    00000140
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppsd-tools_projectpsd-tools---

Explore more