<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:18:33.835137+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-271144</id>
    <title>EUVD-2026-271144</title>
    <updated>2026-10-04T08:18:33.838400+00:00</updated>
    <content>EUVD-2026-271144</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-271144"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27809</id>
    <title>fkie_cve-2026-27809</title>
    <updated>2026-10-04T08:18:33.838438+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row size), decode_rle() raises ValueError which propagated all the way to the user, crashing psd.composite() and psd-tools export. decompress() already had a fallback that replaces failed channels with black pixels when result is None, but it never triggered because the ValueError from decode_rle() was not caught. The fix in version 1.12.2 wraps the decode_rle() call in a try/except so the existing fallback handles the error gracefully.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27809"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-24p2-j2jr-386w</id>
    <title>GHSA-24p2-j2jr-386w — psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps</title>
    <updated>2026-10-04T08:18:33.838507+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: psd-tools</p>
<p>## Summary</p>
<p>A security review of the `psd_tools.compression` module (conducted against the `fix/invalid-rle-compression` branch, commits `7490ffa`–`2a006f5`) identified the following pre-existing issues. The two findings introduced and **fixed** by those commits (Cython buffer overflow, `IndexError` on lone repeat header) are excluded from this report.</p>
<p>---</p>
<p>## Findings</p>
<p>### 1. Unguarded `zlib.decompress` — ZIP bomb / memory exhaustion (Medium)</p>
<p>**Location**: `src/psd_tools/compression/__init__.py`, lines 159 and 162</p>
<p>```python
result = zlib.decompress(data)          # Compression.ZIP
decompressed = zlib.decompress(data)    # Compression.ZIP_WITH_PREDICTION
```</p>
<p>`zlib.decompress` is called without a `max_length` cap. A crafted PSD file containing a ZIP-compressed channel whose compressed payload expands to gigabytes would exhaust process memory before any limit is enforced. The RLE path is not vulnerable to this because the decoder pre-allocates exactly `row_size × height` bytes; the ZIP path has no equivalent ceiling.</p>
<p>**Impact**: Denial-of-service / OOM crash when processing untrusted PSD files.</p>
<p>**Suggested mitigation**: Pass a reasonable `max_length` to `zlib.decompress`, derived from the expected `width * height * depth // 8` byte count already computed in `decompress()`.</p>
<p>---</p>
<p>### 2. No upper-bound validation on image dimensions before allocation (Low)</p>
<p>**Location**: `src/psd_tools/compression/__init__.py`, lines 138 and 193</p>
<p>```python
length = width * height * max(1,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-24p2-j2jr-386w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2262</id>
    <title>PYSEC-2026-2262</title>
    <updated>2026-10-04T08:18:33.838574+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: psd-tools</p>
<p>psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row size), decode_rle() raises ValueError which propagated all the way to the user, crashing psd.composite() and psd-tools export. decompress() already had a fallback that replaces failed channels with black pixels when result is None, but it never triggered because the ValueError from decode_rle() was not caught. The fix in version 1.12.2 wraps the decode_rle() call in a try/except so the existing fallback handles the error gracefully.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27809</id>
    <title>UBUNTU-CVE-2026-27809</title>
    <updated>2026-10-04T08:18:33.838597+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: psd-tools, Ubuntu:25.10: psd-tools, Ubuntu:26.04:LTS: psd-tools</p>
<p>psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row size), decode_rle() raises ValueError which propagated all the way to the user, crashing psd.composite() and psd-tools export. decompress() already had a fallback that replaces failed channels with black pixels when result is None, but it never triggered because the ValueError from decode_rle() was not caught. The fix in version 1.12.2 wraps the decode_rle() call in a try/except so the existing fallback handles the error gracefully.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27809"/>
  </entry>
</feed>
