Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5qjq-93h5-hrgp

Опубликовано: 23 июл. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

pypdf: Possible large memory usage for wrong image dimensions

Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires loading images where the declared size values are much too large compared to the actual data.

Patches

This has been fixed in pypdf==6.14.0.

Workarounds

If you cannot upgrade yet, consider applying the changes from PR #3888.

Пакеты

Наименование

pypdf

pip
Затронутые версииВерсия исправления

< 6.14.0

6.14.0

EPSS

Процентиль: 23%
0.00303
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-789

Связанные уязвимости

CVSS3: 5.3
ubuntu
26 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in version 6.14.0.

CVSS3: 5.3
redhat
26 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in version 6.14.0.

CVSS3: 5.3
nvd
26 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in version 6.14.0.

CVSS3: 5.3
debian
26 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.14 ...

EPSS

Процентиль: 23%
0.00303
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-789