UNKNOWN PyPI
pypdf: Possible large memory usage for wrong image dimensions
PYSEC-2026-3611 · CVE-2026-59938 · GHSA-5qjq-93h5-hrgp
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires loading images where the declared size values are much too large compared to the actual data.
Patches
This has been fixed in pypdf==6.14.0.
Workarounds
If you cannot upgrade yet, consider applying the changes from PR #3888.
References
- WEB https://github.com/py-pdf/pypdf/security/advisories/GHSA-5qjq-93h5-hrgp
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-59938
- WEB https://github.com/py-pdf/pypdf/pull/3888
- WEB https://github.com/py-pdf/pypdf/commit/c64583be16b8e8763d8777075f8ecbf382014b7a
- PACKAGE https://github.com/py-pdf/pypdf
- WEB https://github.com/py-pdf/pypdf/releases/tag/6.14.0
- PACKAGE https://pypi.org/project/pypdf
- ADVISORY https://github.com/advisories/GHSA-5qjq-93h5-hrgp
Ready to move
Start Securing
Free, no credit card | First findings in minutes