Sploitus

CVE-2026-25990

1 known exploit for CVE-2026-25990

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

Affected products
Pillow, Red Os
Python Pillow
< 12.1.1
Fix
Available
CVSS 4.0
8.6 HIGH
CVSS 3.1
7.5 HIGH
EPSS
0.4% (30th percentile)
Weakness
CWE-787
NVD status
Modified
Published
2026-02-11
CVE-2026-25990 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-25990

Proof-of-concept code and exploit modules indexed by Sploitus