CVE-2020-10571Critical· 9.8▾ MidnightPotential buffer overflow in psd-tools
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
1.8%
An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malformed PSD input data during decoding to the PIL.Image or NumPy format, leading to a Buffer Overflow.
Users of psd-tools version v1.8.37 to v1.9.3 should upgrade to v1.9.4.
Without Cython present on installation, buffer overflow does not occur but IndexError will be thrown. However, already installed psd-tools with Cython extention should be upgraded.
https://github.com/psd-tools/psd-tools/pull/198
If you have any questions or comments about this advisory:
psd-tools >= 1.8.37, <= 1.9.3Upgrade to a patched release:
psd-tools 1.9.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59991High· 7.5psd-tools is a Python package for working with Adobe Photoshop PSD files
CVE-2026-27809Mediumpsd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
CVE-2026-49836Medium· 4.6psd-tools: arbitrary file write via smart-object filename
CVE-2026-87012Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
CVE-2024-38355Medium· 7.3socket.io has an unhandled 'error' event
CVE-2026-73549Medium· 5.3Envoy is an open source edge and service proxy designed for cloud-native applications