PT-2026-96971 · Pypi · Psd-Tools

CVE-2026-59991

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions psd-tools versions prior to 1.17.4
Description An issue exists where the PSDImage.composite() and PSDImage.numpy() functions allocate output buffers based on geometry specified in the PSD header—including width, height, channels, depth, and per-layer rectangles—before validating these values against the actual file data. A small, specially crafted PSD file can trigger multi-gigabyte memory allocations. In the case of PSDImage.composite(), the function may return a black image with only a warning instead of raising an exception, preventing the caller from detecting the failure. This can lead to a denial of service where services processing untrusted PSD files are terminated by out-of-memory (OOM) handling.
Recommendations Update to version 1.17.4.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59991
GHSA-8Q6G-VJHF-JP8M

Affected Products

Psd-Tools