CVE-2026-59938

MEDIUM

pypdf: Possible large memory usage for wrong image dimensions

Title source: cna
STIX 2.1

Description

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in version 6.14.0.

References (4)

Core 4

Scores

CVSS v3 5.3
EPSS 0.0030
EPSS Percentile 22.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-789
Status published
Products (3)
py-pdf/pypdf < 6.14.0
pypdf_project/pypdf < 6.14.0
pypi/pypdf 0 - 6.14.0PyPI
Published Jul 08, 2026
Tracked Since Jul 08, 2026