Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-42311

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.7%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2026-42311
  • Python » Pillow » Version: 10.3.0
    cpe:2.3:a:python:pillow:10.3.0
  • Python » Pillow » Version: 10.4.0
    cpe:2.3:a:python:pillow:10.4.0
  • Python » Pillow » Version: 11.0.0
    cpe:2.3:a:python:pillow:11.0.0
  • Python » Pillow » Version: 11.1.0
    cpe:2.3:a:python:pillow:11.1.0
  • Python » Pillow » Version: 11.2.1
    cpe:2.3:a:python:pillow:11.2.1
  • Python » Pillow » Version: 11.3.0
    cpe:2.3:a:python:pillow:11.3.0
  • Python » Pillow » Version: 12.0.0
    cpe:2.3:a:python:pillow:12.0.0


Contact Us

Shodan ® - All rights reserved