Multiple security vulnerabilities affecting pypdf versions < 6.14.0 affecting pypdf versions < 6.14.1 have been identified in pypdf. These issues can lead to large memory usage, long runtimes, and infinite loops when parsing maliciously crafted PDF files. The affected version range is < 6.14.2.
CVE-2026-59938 (CVSS 6.9 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to large memory usage by loading images with declared size values that are much too large compared to the actual data.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting pypdf versions < 6.14.0 affecting pypdf versions < 6.14.1 have been identified in pypdf. These issues can lead to large memory usage, long runtimes, and infinite loops when parsing maliciously crafted PDF files. The affected version range is < 6.14.2.
CVE-2026-59938 (CVSS 6.9 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to large memory usage by loading images with declared size values that are much too large compared to the actual data.[emaillocker id="1283"]
CVE-2026-59937 (CVSS 6.9 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to long runtimes by creating cross-reference streams with repeated malformed cross-reference streams.
CVE-2026-59936 (CVSS 8.7 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop by parsing the content stream of a page with a not terminated inline image, as done when extracting the page text for example.
CVE-2026-59935 (CVSS 8.7 — Severity): An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop by parsing the content stream of a page with a not terminated inline image, specifically in ASCII85 and ASCIIHex filters, as done when extracting the page text for example. These vulnerabilities collectively present a significant risk to users who rely on pypdf. Administrators should review their exposure and apply updates to mitigate these risks. These vulnerabilities collectively present a significant risk to users who rely on pypdf.
These vulnerabilities collectively present a significant risk to users who rely on pypdf.
We recommend you to update pypdf to version 6.14.0 or 6.14.1 or 6.14.2 depending on your installed branch.
The following reports contain further technical details:
[/emaillocker]