UNKNOWN PyPI

pypdf: Possible large memory usage for wrong image dimensions

PYSEC-2026-3611 · CVE-2026-59938 · GHSA-5qjq-93h5-hrgp

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires loading images where the declared size values are much too large compared to the actual data.

Patches

This has been fixed in pypdf==6.14.0.

Workarounds

If you cannot upgrade yet, consider applying the changes from PR #3888.

Ready to move

Start Securing

Free, no credit card | First findings in minutes