CVE-2026-27809 is a critical vulnerability affecting the psd-tools Python package (versions prior to 1.12.2), which is used for processing Adobe Photoshop PSD files. Malformed RLE-compressed image data within a PSD file can cause a ValueError, leading to a denial-of-service condition by crashing psd.composite() and psd-tools export functions. Rated with a CVSS score of 9.1 (CRITICAL), this vulnerability is remotely exploitable with low attack complexity and no user interaction required, potentially leading to high impact on availability and integrity. The issue stems from improper error handling (CWE-755) when decoding RLE data. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While it is not on the CISA KEV catalog, there has been some community discussion, indicating awareness of the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12.2CPE matchmatch criteria | cpe:2.3:a:psd-tools_project:psd-tools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.