CVE-2026-42311

EUVD-2026-28903
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
Affected Products (NVD)
VendorProductVersion
pythonpillow
10.3.0 ≤
𝑥
< 12.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pillow
bookworm
9.4.0-1.1+deb12u1
fixed
bookworm (security)
9.4.0-1.1+deb12u1
fixed
bullseye
8.1.2+dfsg-0.3+deb11u2
fixed
bullseye (security)
8.1.2+dfsg-0.3+deb11u3
fixed
forky
12.2.0-1
fixed
sid
12.2.0-1
fixed
trixie
vulnerable
trixie (security)
11.1.0-5+deb13u3
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python-pillow
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.18
fixed
python-pillow-debuginfo
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.18
fixed
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python-pillow-debugsource
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python-pillow-devel
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.18
fixed
python-pillow-doc
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.18
fixed
python-pillow-sane
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.18
fixed
python-pillow-tk
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.18
fixed
python3-pillow
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python3-pillow-debuginfo
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python3-pillow-devel
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python3-pillow-tk
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed
python3-pillow-tk-debuginfo
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.8
fixed