CVE-2026-25990High· 7.5▾ TwilightPillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
0.4% → 0.4%
Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.
pillow >= 10.3.0, < 12.1.1Upgrade past the affected range:
pillow 12.1.1Affected packages:
pillow >= 10.3.0, < 12.1.1Patched in:
pillow 12.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40192High· 7.5Pillow is a Python imaging library
CVE-2026-21441High· 7.5urllib3 is an HTTP client library for Python
CVE-2026-44432High· 7.5urllib3 is an HTTP client library for Python
CVE-2025-15467High· 8.8Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, …
CVE-2025-48379High· 7.1Pillow is a Python imaging library
CVE-2023-50447High· 8.1Arbitrary Code Execution in Pillow