---
schema_version: '1.0'
id: security-20260714-c572fa
url: https://osv.dev/vulnerability/PYSEC-2026-2252
url_hash: c572fa513911b6819c0051ab7c43640f5c61ff8b8dae392944f8c48a01c644f6
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-2252
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-42311
- PYSEC-2026-2252
- severity:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- pillow
- PyPI
lang: en
published_at: '2026-05-09T06:16:10Z'
fetched_at: '2026-07-14T06:42:23Z'
updated_at: '2026-07-14T06:43:41Z'
status: published
content_hash: baa997570108f951b9e5451e35015b4bede8035e56ade36087d9c0be1a4d411d
license_note: full
summary: Pillow is a Python imaging library. From version 10.3.0 to before version
  12.2.0, processing a malicious PSD file could lead to memory corruption, potentially
  resulting in a crash or arbitrary code execution. This issue has been patched in
  version 12.2.0.
summary_source: rss
summary_en: Pillow is a Python imaging library. From version 10.3.0 to before version
  12.2.0, processing a malicious PSD file could lead to memory corruption, potentially
  resulting in a crash or arbitrary code execution. This issue has been patched in
  version 12.2.0.
entities:
- name: Pillow
  type: artifact
key_facts: []
related: []
related_auto: []
title: CVE-2026-42311 — pillow
---

# CVE-2026-42311 — pillow

## TL;DR
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

## Key Points
- cve / CVE-2026-42311 / PYSEC-2026-2252 / severity:CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H / pillow / PyPI

## Details
**Severity:** CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
**Advisory:** PYSEC-2026-2252 (CVE-2026-42311)

**Affected (your watchlist):**
- `PyPI:pillow` 12.1.1 → fixed in 12.2.0 [docker/docker-llmwiki]

**Details:**
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

**References:**
- https://github.com/python-pillow/Pillow/releases/tag/12.2.0
- https://github.com/python-pillow/Pillow/commit/58f9a1d166dcb0c274807d4423522d205b0c35ea
- https://github.com/python-pillow/Pillow/pull/9520
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-pwv6-vv43-88gr

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-2252_

## Source
元記事: [CVE-2026-42311 — pillow](https://osv.dev/vulnerability/PYSEC-2026-2252) — published 2026-05-09T06:16:10Z
