Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g867-7843-wf8q

Опубликовано: 23 июл. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7

Описание

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page with a not terminated inline image, as done when extracting the page text for example. It only affects the ASCII85 and ASCIIHex filters.

Patches

This has been fixed in pypdf==6.14.2.

Workarounds

If you cannot upgrade yet, consider applying the changes from PR #3892.

Пакеты

Наименование

pypdf

pip
Затронутые версииВерсия исправления

< 6.14.2

6.14.2

EPSS

Процентиль: 27%
0.00352
Низкий

8.7 High

CVSS4

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
26 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2.

CVSS3: 6.5
redhat
26 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2.

CVSS3: 7.5
nvd
26 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2.

CVSS3: 7.5
debian
26 дней назад

pypdf is a free and open-source pure-python PDF library. Prior to 6.14 ...

EPSS

Процентиль: 27%
0.00352
Низкий

8.7 High

CVSS4

Дефекты

CWE-835