GHSA-cfh3-3jmp-rvhc

Suggest an improvement
Source
https://github.com/advisories/GHSA-cfh3-3jmp-rvhc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-cfh3-3jmp-rvhc/GHSA-cfh3-3jmp-rvhc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cfh3-3jmp-rvhc
Aliases
Related
Published
2026-02-11T14:22:50Z
Modified
2026-02-12T23:43:43.057602Z
Severity
  • 8.9 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Pillow affected by out-of-bounds write when loading PSD images
Details

Impact

An out-of-bounds write may be triggered when loading a specially crafted PSD image. Pillow >= 10.3.0 users are affected.

Patches

Pillow 12.1.1 will be released shortly with a fix for this.

Workarounds

Image.open() has a formats parameter that can be used to prevent PSD images from being opened.

References

Pillow 12.1.1 will add release notes at https://pillow.readthedocs.io/en/stable/releasenotes/index.html

Database specific
{
    "nvd_published_at": "2026-02-11T21:16:20Z",
    "cwe_ids": [
        "CWE-787"
    ],
    "github_reviewed_at": "2026-02-11T14:22:50Z",
    "severity": "HIGH",
    "github_reviewed": true
}
References

Affected packages

PyPI / pillow

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10.3.0
Fixed
12.1.1

Affected versions

10.*
10.3.0
10.4.0
11.*
11.0.0
11.1.0
11.2.1
11.3.0
12.*
12.0.0
12.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-cfh3-3jmp-rvhc/GHSA-cfh3-3jmp-rvhc.json"