Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59935

Опубликовано: 08 июл. 2026
Источник: debian

Описание

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pypdfunfixedpackage
pypdfno-dsatrixiepackage
pypdfpostponedbookwormpackage
pypdf2removedpackage
pypdf2postponedbookwormpackage
pypdf2postponedbullseyepackage

Примечания

  • https://github.com/py-pdf/pypdf/security/advisories/GHSA-g867-7843-wf8q

  • https://github.com/py-pdf/pypdf/pull/3892

  • Fixed by: https://github.com/py-pdf/pypdf/commit/5a33a46416aa1ae6c025ff90a3cca57631fdafd2 (6.14.2)

Связанные уязвимости

CVSS3: 7.5
ubuntu
26 дней назад

(pypdf is a free and open-source pure-python PDF library. Prior to 6.14 ...)

CVSS3: 6.5
redhat
26 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2.

CVSS3: 7.5
nvd
26 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2.