PT-2026-56528 · Pypi · Pypdf

·

CVE-2026-59938

·

Published

2026-07-08

·

Updated

2026-08-04

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pypdf versions prior to 6.14.0
Description An attacker can craft a PDF file with declared image size values that are significantly larger than the actual data. This leads to excessive memory consumption during the image parsing process within the library.
Recommendations Update to version 6.14.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-EH47852
CLEANSTART-2026-GN02455
CVE-2026-59938
ECHO-6652-DA99-9F06
GHSA-5QJQ-93H5-HRGP
PYSEC-2026-3611

Affected Products

Pypdf