Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66019

Опубликовано: 26 нояб. 2025
Источник: nvd
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

EPSS

Процентиль: 22%
0.00073
Низкий

Дефекты

CWE-400

Связанные уязвимости

ubuntu
2 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

debian
2 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to vers ...

github
2 месяца назад

pypdf's LZWDecode streams be manipulated to exhaust RAM

EPSS

Процентиль: 22%
0.00073
Низкий

Дефекты

CWE-400