CVE-2026-25990 | python-pillow Pillow up to 12.1.0 PSD Image Parser out-of-bounds write (GHSA-cfh3-3jmp-rvhc / Nessus ID 298710)
A vulnerability was found in python-pillow Pillow up to 12.1.0. It has been classified as critical. Impacted is an unknown function of the component PSD Image Parser. The manipulation leads to out-of-bounds write.
This vulnerability is documented as CVE-2026-25990. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.