---
id: CVE-2026-42311
title: >-
  Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file
  processing (CVE-2026-42311)
summary: >-
  A flaw was found in Pillow, a Python imaging library. An attacker could
  exploit this vulnerability by tricking a user into processing a specially
  crafted malicious PSD file. This could lead to memory corruption, potentially
  causing the app…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-120
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - exploit_intelligence
  - openshift_lightspeed
  - ai_inference_server
  - ansible_automation_platform 2
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - quay 3
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - ai_inference_server 3.4
  - openshift_ai 3.4
patched:
  - ai_inference_server 3.2
  - ai_inference_server 3.3
  - ai_inference_server 3.4
  - openshift_ai 3.4
published: '2026-05-09'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T05:56:54+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42311.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42311.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42311'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2468459'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-42311'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42311'
  - url: >-
      https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea
  - url: 'https://github.com/python-pillow/Pillow/pull/9520'
  - url: 'https://github.com/python-pillow/Pillow/releases/tag/12.2.0'
  - url: >-
      https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr
  - url: 'https://access.redhat.com/errata/RHSA-2026:61628'
  - url: 'https://access.redhat.com/errata/RHSA-2026:16008'
  - url: 'https://access.redhat.com/errata/RHSA-2026:16030'
  - url: 'https://access.redhat.com/errata/RHSA-2026:16009'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70969'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57387'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69464'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: >-
      https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc
  - url: 'https://github.com/python-pillow/Pillow'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00217
epssPercentile: 0.10714
aliases:
  - GHSA-pwv6-vv43-88gr
  - BIT-pillow-2026-42311
  - PYSEC-2026-2252
ecosystem: pip
ingestedAt: '2026-07-13T18:58:01.696Z'
---

## Overview

A flaw was found in Pillow, a Python imaging library. An attacker could exploit this vulnerability by tricking a user into processing a specially crafted malicious PSD file. This could lead to memory corruption, potentially causing the application to crash or allowing for arbitrary code execution.

## Vendor advisories

- **RHSA-2026:61628** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61628)
- **RHSA-2026:16008** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16008)
- **RHSA-2026:16030** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16030)
- **RHSA-2026:16009** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16009)
- **RHSA-2026:70969** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70969)
- **RHSA-2026:57387** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-08-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:57387)
- **RHSA-2026:69464** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69464)
- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · no fix planned: Exploit Intelligence, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, OpenShift Lightspeed, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42311.json)

**Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing** — rated Important by Red Hat. Released 2026-05-09, updated 2026-09-24.

Affected:

- Exploit Intelligence
- OpenShift Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Quay 3

Fixed:

- Red Hat AI Inference Server 3.2
- Red Hat AI Inference Server 3.3
- Red Hat AI Inference Server 3.4
- Red Hat OpenShift AI 3.4

No fix planned:

- Exploit Intelligence
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- OpenShift Lightspeed
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Quay 3

Not affected:

- Red Hat OpenShift AI 3.4
- Lightspeed Core
- OpenShift Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat Quay 3

## Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:61628 https://access.redhat.com/errata/RHSA-2026:61628
For more information visit https://access.redhat.com/errata/RHSA-2026:16008 https://access.redhat.com/errata/RHSA-2026:16008
For more information visit https://access.redhat.com/errata/RHSA-2026:16030 https://access.redhat.com/errata/RHSA-2026:16030

Workarounds / mitigations:

- To mitigate this vulnerability, users should avoid processing untrusted or suspicious PSD image files with applications that utilize the Pillow library. Implementing strict input validation and sanitization for image uploads and processing workflows can reduce the risk. Additionally, running applications that process untrusted content within a sandboxed environment can limit the potential impact of successful exploitation.

## Package advisory (CVE-2026-42311)

Affected packages:

- `pillow >= 10.3.0, < 12.2.0`

Patched in:

- `pillow 12.2.0`

Source: https://osv.dev/vulnerability/GHSA-pwv6-vv43-88gr
