← Zurück zur CVE-Suche

CVE-2026-59938

pypdf

Beschreibung

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in version 6.14.0.

CVSS 6.9EPSS 0.303%Risiko 0.71
Quelle öffnen
Veröffentlicht
2026-07-08 18:16:35
Betroffene Versionen
<6.14.0
Typ
Bibliothek
Vektor
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X