PT-2026-96971 · Pypi · Psd-Tools
CVE-2026-59991
·
Published
2026-09-22
·
Updated
2026-09-23
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
psd-tools versions prior to 1.17.4
Description
An issue exists where the
PSDImage.composite() and PSDImage.numpy() functions allocate output buffers based on geometry specified in the PSD header—including width, height, channels, depth, and per-layer rectangles—before validating these values against the actual file data. A small, specially crafted PSD file can trigger multi-gigabyte memory allocations. In the case of PSDImage.composite(), the function may return a black image with only a warning instead of raising an exception, preventing the caller from detecting the failure. This can lead to a denial of service where services processing untrusted PSD files are terminated by out-of-memory (OOM) handling.Recommendations
Update to version 1.17.4.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Psd-Tools