Threat Advisory

pypdf Flaw Lets Attackers Craft Large Memory Usage PDFs

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting pypdf versions < 6.14.0 affecting pypdf versions < 6.14.1 have been identified in pypdf. These issues can lead to large memory usage, long runtimes, and infinite loops when parsing maliciously crafted PDF files. The affected version range is < 6.14.2.

CVE-2026-59938 (CVSS 6.9 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to large memory usage by loading images with declared size values that are much too large compared to the actual data.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting pypdf versions < 6.14.0 affecting pypdf versions < 6.14.1 have been identified in pypdf. These issues can lead to large memory usage, long runtimes, and infinite loops when parsing maliciously crafted PDF files. The affected version range is < 6.14.2.

CVE-2026-59938 (CVSS 6.9 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to large memory usage by loading images with declared size values that are much too large compared to the actual data.[emaillocker id="1283"]

CVE-2026-59937 (CVSS 6.9 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to long runtimes by creating cross-reference streams with repeated malformed cross-reference streams.

CVE-2026-59936 (CVSS 8.7 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop by parsing the content stream of a page with a not terminated inline image, as done when extracting the page text for example.

CVE-2026-59935 (CVSS 8.7 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop by parsing the content stream of a page with a not terminated inline image, specifically in ASCII85 and ASCIIHex filters, as done when extracting the page text for example. These vulnerabilities collectively present a significant risk to users who rely on pypdf. Administrators should review their exposure and apply updates to mitigate these risks. These vulnerabilities collectively present a significant risk to users who rely on pypdf.

These vulnerabilities collectively present a significant risk to users who rely on pypdf.

RECOMMENDATION:

We recommend you to update pypdf to version 6.14.0 or 6.14.1 or 6.14.2 depending on your installed branch.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu