Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66019

Опубликовано: 26 нояб. 2025
Источник: nvd
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

EPSS

Процентиль: 28%
0.00353
Низкий

Дефекты

CWE-400

Связанные уязвимости

ubuntu
8 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

CVSS3: 5.3
redhat
8 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

debian
8 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to vers ...

github
8 месяцев назад

pypdf's LZWDecode streams be manipulated to exhaust RAM

CVSS3: 7.5
fstec
10 месяцев назад

Уязвимость библиотеки Python для работы с PDF файлами PyPDF, связанная с некорректной обработкой сильно сжатых входных данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 28%
0.00353
Низкий

Дефекты

CWE-400