
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27809 is a denial-of-service vulnerability in the psd-tools Python package (used for processing Adobe Photoshop PSD files) affecting all versions prior to 1.12.2. The vulnerability stems from multiple hardening gaps in the psd_tools.compression module, most critically: unguarded zlib.decompress() calls susceptible to ZIP bomb/memory exhaustion attacks, missing dimension validation before memory allocation, and an uncaught ValueError from decode_rle() that crashes psd.composite() and export operations. The advisory was published on February 25, 2026, with a patch released the same day (Github Advisory). CVSS v3.1 base score is 9.1 (Critical) per NVD; the CNA (GitHub) rates it 6.8 (Medium) under CVSS v4.0 (Github Advisory).
The vulnerability encompasses several weaknesses in src/psd_tools/compression/__init__.py and the Cython extension _rle.pyx. The primary issues are: (1) CWE-409 / CWE-789: zlib.decompress() is called without a max_length cap for ZIP and ZIP_WITH_PREDICTION compression paths, allowing a crafted ZIP-bomb payload to exhaust process memory; (2) CWE-755: decode_rle() raises ValueError for malformed RLE data (e.g., literal runs extending past row size), which propagated uncaught to the caller, bypassing the existing black-pixel fallback in decompress(); (3) CWE-617: An assert statement used as a runtime integrity check could be silently disabled with Python's -O flag; (4) CWE-704 / CWE-190: Cython loop indices declared as cdef int (32-bit) compared against Py_ssize_t (64-bit), creating potential undefined behavior for row sizes exceeding INT_MAX; (5) CWE-789: No upper-bound validation on width, height, or depth before memory allocation, allowing adversarially crafted PSB files to trigger uncontrolled allocation attempts (Github Advisory, Patch Commit).
Successful exploitation causes denial of service by crashing any application that uses psd-tools to process untrusted PSD files — specifically, psd.composite() and export operations terminate with an unhandled exception. The ZIP bomb vector can additionally exhaust all available process memory before any OS-level limit intervenes, potentially affecting system stability beyond the Python process itself. There is no confidentiality impact; integrity is rated High under CVSS v3.1 due to the potential for silent data degradation (malformed channels silently replaced with black pixels in some code paths). Lateral movement is not a concern, but any web service or pipeline that automatically ingests PSD files from untrusted sources is directly at risk (Github Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation as of the advisory date (Github Advisory). The EPSS score is approximately 0.04% (23rd percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Exploitation requires only the ability to supply a crafted PSD file to an application using a vulnerable version of psd-tools — no authentication, privileges, or user interaction are needed, making it trivially automatable against exposed file-processing endpoints.
psd-tools < 1.12.2 (e.g., image conversion services, design tools, CI/CD asset pipelines).decode_rle() to raise ValueError, which propagates uncaught through decompress() to crash the application.zlib.decompress() is called without a max_length cap, this exhausts process memory.psd.composite(), export, or PSDImage.open()) raises an unhandled exception or OOM error, resulting in service unavailability (Github Advisory, Patch Commit).ValueError or MemoryError tracebacks in application logs originating from psd_tools/compression/__init__.py or decode_rle(); repeated crash/restart cycles of the PSD-processing worker process.psd.composite() or export operations consistently failing with ValueError or IndexError exceptions when processing specific uploaded files; PSDDecompressionWarning warnings emitted in logs (post-patch indicator of attempted exploitation against patched systems) (Github Advisory).Primary remediation: Upgrade psd-tools to version 1.12.2 or later immediately (pip install --upgrade psd-tools). Version 1.12.2 introduces: a _safe_zlib_decompress() helper with a hard max_length cap to prevent ZIP bombs; dimension validation (width/height in [1, 300,000], depth in {1, 8, 16, 32}) before any allocation; try/except wrapping of decode_rle() to activate the existing black-pixel fallback; replacement of assert with explicit raise ValueError; and Cython type fixes (Patch Commit, Release Notes). Workarounds (if immediate patching is not possible): reject PSD/PSB files from untrusted sources at the application or network layer; disable automatic PSD processing features; run the PSD-processing worker in an isolated process with memory limits (e.g., ulimit -v) to contain ZIP bomb impact (Github Advisory).
The advisory was published by the repository maintainer (kyamagu) on February 25, 2026, and reviewed by GitHub's advisory database the following day. A community write-up titled "Death by Pixels: Unpacking CVE-2026-27809 in psd-tools" was published on dev.to shortly after disclosure. Red Hat acknowledged the CVE on February 27, 2026, and Tenable released a Nessus detection plugin (ID 300480) in early March 2026. No significant controversy or widespread media coverage has been identified; community reaction has been limited to standard vulnerability tracking and patching discussions (Github Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."