Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pwv6-vv43-88gr | Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow) |
Thu, 14 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python
Python pillow |
|
| CPEs | cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Python
Python pillow |
|
| Metrics |
cvssV3_1
|
Tue, 12 May 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 09 May 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python-pillow
Python-pillow pillow |
|
| Vendors & Products |
Python-pillow
Python-pillow pillow |
Sat, 09 May 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0. | |
| Title | Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow) | |
| Weaknesses | CWE-190 CWE-787 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-12T02:24:33.053Z
Reserved: 2026-04-26T12:37:18.169Z
Link: CVE-2026-42311
Updated: 2026-05-12T02:24:28.685Z
Status : Analyzed
Published: 2026-05-09T06:16:10.430
Modified: 2026-05-14T20:27:45.590
Link: CVE-2026-42311
No data.
OpenCVE Enrichment
Updated: 2026-05-09T07:00:11Z
Github GHSA