{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apsd-tools_projectpsd-toolspython/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:psd-tools_project:psd-tools:*:*:*:*:*:python:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["psd-tools (\u003c 1.17.4)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Python library psd-tools, version 1.17.2 and earlier, is vulnerable to an uncontrolled memory allocation flaw (CVE-2026-59991). When processing a PSD file, the \u003ccode\u003ePSDImage.composite()\u003c/code\u003e and \u003ccode\u003ePSDImage.numpy()\u003c/code\u003e functions allocate an output image buffer based on dimensions declared within the PSD file's header before validating these dimensions against the actual file size or reasonable constraints.\u003c/p\u003e\n\u003cp\u003eAn attacker can provide a small, maliciously crafted PSD file, as small as 49 bytes, that declares extremely large width, height, or layer dimensions. This forces the application to commit gigabytes of memory for the buffer, far exceeding the size of the input file. Because the library fails to throw an exception upon detecting mismatched geometry and instead returns a black image, the caller is unable to detect the malicious nature of the file. This vulnerability is critical for web services or backend applications that process untrusted user-supplied images, as it allows for an unrecoverable out-of-memory (OOM) kill of the host process with minimal bandwidth usage.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a denial-of-service condition due to host system resource exhaustion. An attacker can crash web servers or background job workers processing image uploads by committing up to 32 GB of memory from a single, sub-100-byte payload. This poses a significant threat to any service or application that allows users to upload PSD files for processing, indexing, or format conversion.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade psd-tools to version 1.17.4 or later immediately to include validation logic that mitigates memory over-allocation.\u003c/li\u003e\n\u003cli\u003eImplement a maximum file size limit and a maximum pixel dimension check for all user-supplied image uploads at the application layer before passing the data to the psd-tools library.\u003c/li\u003e\n\u003cli\u003eMonitor logs for repeated service restarts or process crashes involving \u003ccode\u003epsd-tools\u003c/code\u003e to identify potential exploitation attempts.\u003c/li\u003e\n\u003cli\u003eUse the provided SHA-256 hash (7d8ebf03a54393cb0359ecf4b676d1b08c9a8c6afdd06671ef406d6893cce826) to scan existing file storage for known malicious PoC payloads.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T19:53:29Z","date_published":"2026-09-22T19:53:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-psd-tools-memory-dos/","summary":"An improper input validation vulnerability in psd-tools (CVE-2026-59991) allows attackers to trigger massive, unvalidated memory allocations using maliciously crafted PSD files, leading to OOM-kill of the host service.","title":"Denial of Service via Uncontrolled Memory Allocation in psd-tools","url":"https://feed.craftedsignal.io/briefs/2026-09-psd-tools-memory-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:psd-Tools_project:psd-Tools:*:*:*:*:*:python:*:*","version":"https://jsonfeed.org/version/1.1"}