Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.
CVSS Details
- CVSS 4.0 Base Score: 8.6 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-pillow | Feb 16, 2026 | Feb 11, 2026 |
| Amazon Linux Ami 2 | — | Upgrade python-pillow-saneUpgrade python-pillow-develUpgrade python-pillow-debuginfoUpgrade python-pillow-docUpgrade python-pillowUpgrade python-pillow-tk | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade python3-pillow-tkUpgrade python3-pillow-debuginfoUpgrade python3-pillowUpgrade python3-pillow-tk-debuginfoUpgrade python3-pillow-develUpgrade python-pillow-debuginfoUpgrade python-pillow-debugsource | Mar 9, 2026 | Feb 11, 2026 |
| Debian | — | Upgrade pillow | Jul 23, 2026 | Jul 23, 2026 |
| Ubuntu | — | Upgrade python3-pil | Feb 18, 2026 | Feb 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub