feat(deps): [SECURITY] Update dependency pillow to <12.1.2,>=12.1.1 [SECURITY] #558
Reference in New Issue
Block a user
Delete Branch "renovate/pypi-pillow-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
<12.1.1,>=12.1.0→<12.1.2,>=12.1.1Pillow affected by out-of-bounds write when loading PSD images
CVE-2026-25990 / GHSA-cfh3-3jmp-rvhc
More information
Details
Impact
An out-of-bounds write may be triggered when loading a specially crafted PSD image. Pillow >= 10.3.0 users are affected.
Patches
Pillow 12.1.1 will be released shortly with a fix for this.
Workarounds
Image.open()has aformatsparameter that can be used to prevent PSD images from being opened.References
Pillow 12.1.1 will add release notes at https://pillow.readthedocs.io/en/stable/releasenotes/index.html
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:PReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
python-pillow/Pillow (pillow)
v12.1.1Compare Source
https://pillow.readthedocs.io/en/stable/releasenotes/12.1.1.html
Dependencies
Other changes
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
[SECURITY] Update dependency pillow to <12.1.2,>=12.1.1 [SECURITY]to feat(deps): [SECURITY] Update dependency pillow to <12.1.2,>=12.1.1 [SECURITY]5b4c860878to1cc7c0cf73New commits pushed, approval review dismissed automatically according to repository settings